| services.dnscrypt-proxy2.settings | Attrset that is converted and passed as TOML config file
|
| services.dnscrypt-proxy2.configFile | Path to TOML config file
|
| services.dnscrypt-proxy2.upstreamDefaults | Whether to base the config declared in services.dnscrypt-proxy2.settings on the upstream example config (https://github.com/DNSCrypt/dnscrypt-proxy/blob/master/dnscrypt-proxy/example-dnscrypt-proxy.toml)
Disable this if you want to declare your dnscrypt config from scratch.
|
| services.dnscrypt-proxy2.enable | Whether to enable dnscrypt-proxy2.
|
| services.dnscrypt-proxy.configFile | Path to TOML config file
|
| services.dnscrypt-proxy.upstreamDefaults | Whether to base the config declared in services.dnscrypt-proxy.settings on the upstream example config (https://github.com/DNSCrypt/dnscrypt-proxy/blob/master/dnscrypt-proxy/example-dnscrypt-proxy.toml)
Disable this if you want to declare your dnscrypt config from scratch.
|
| services.dnscrypt-proxy.settings | Attrset that is converted and passed as TOML config file
|
| services.lact.settings | Settings for LACT
|
| services.mjolnir.settings | Additional settings (see mjolnir default config for available settings)
|
| services.nitter.settings | Add settings here to override NixOS module generated settings
|
| boot.uki.settings | The configuration settings for ukify
|
| services.amule.settings | Free form attribute set for aMule settings
|
| services.odoo.settings | Odoo configuration settings
|
| services.ncdns.settings | ncdns settings
|
| services.sslh.settings | sslh configuration
|
| services.davfs2.settings | Extra settings appended to the configuration of davfs2
|
| services.newt.settings | Settings for Newt module, see Newt CLI docs for more information.
|
| services.xray.settings | The configuration object
|
| services.picom.settings | Picom settings
|
| services.ntpd-rs.settings | Settings to write to ntp.toml
See https://docs.ntpd-rs.pendulum-project.org/man/ntp.toml.5
for more information about available options.
|
| services.auto-epp.settings | Settings for the auto-epp application
|
| services.marytts.settings | Settings for MaryTTS
|
| services.rimgo.settings | Settings for rimgo, see the official documentation for supported options.
|
| services.searx.settings | Searx settings
|
| services.acme-dns.settings | Free-form settings written directly to the acme-dns.cfg file
|
| services.stubby.settings | Content of the Stubby configuration file
|
| services.redlib.settings | See GitHub for available settings.
|
| services.movim.settings | .env settings for Movim
|
| services.lldap.settings | Free-form settings written directly to the lldap_config.toml file
|
| services.hickory-dns.settings | Settings for hickory-dns
|
| services.aria2.settings | Generates the aria2.conf file
|
| services.wakapi.settings | Settings for Wakapi
|
| services.screego.settings | Screego settings passed as Nix attribute set, they will be merged with
the defaults
|
| services.h2o.settings | Configuration for H2O (see https://h2o.examp1e.net/configure.html)
|
| services.gokapi.settings | Configuration settings for the generated config json file
|
| services.g3proxy.settings | Settings of g3proxy.
|
| services.mailman.settings | Settings for mailman.cfg
|
| services.tor.settings | See torrc manual
for documentation.
|
| services.hercules-ci-agent.settings | These settings are written to the agent.toml file
|
| services.privoxy.settings | This option is mapped to the main Privoxy configuration file
|
| services.n8n.settings | Configuration for n8n, see https://docs.n8n.io/hosting/environment-variables/configuration-methods/
for supported values.
|
| services.misskey.settings.db | Database settings.
|
| services.opengfw.settings.io | IO settings.
|
| services.logrotate.settings | logrotate freeform settings: each attribute here will define its own section,
ordered by services.logrotate.settings.<name>.priority,
which can either define files to rotate with their settings
or settings common to all further files settings
|
| services.sanoid.settings | Free-form settings written directly to the config file
|
| services.sssd.settings | Contents of sssd.conf.
|
| services.rauc.slots.<name>.*.settings | Settings for this slot.
|
| services.pgadmin.settings | Settings for pgadmin4.
Documentation
|
| services.maubot.settings | YAML settings for maubot
|
| services.tlp.settings | Options passed to TLP
|
| services.fluent-bit.settings | See configurationFile.
configurationFile takes precedence over settings.
|
| services.knot.settings | Extra configuration as nix values.
|
| services.umurmur.settings | Settings of uMurmur
|
| services.draupnir.settings | Free-form settings written to Draupnir's configuration file
|
| services.openbao.settings | Settings of OpenBao
|
| services.opengfw.settings | Settings passed to OpenGFW. Example config
|
| services.pretix.settings | pretix configuration as a Nix attribute set
|
| services.bee.settings | Ethereum Swarm Bee configuration
|
| services.private-gpt.settings | settings-local.yaml for private-gpt
|
| services.qui.settings.port | The port qui listens on.
|
| services.ntfy-sh.settings | Configuration for ntfy.sh, supported values are here.
|
| services.turn-rs.settings | Turn-rs server config file
|
| services.ifm.settings | Configuration of the IFM service
|
| services.lemmy.settings | Lemmy configuration
|
| services.aesmd.settings | AESM configuration
|
| services.stash.settings | Stash configuration
|
| services.eintopf.settings | Settings to configure web service
|
| services.evremap.settings | Settings for evremap
|
| services.qui.settings.host | The host address qui listens on.
|
| services.frp.settings | Frp configuration, for configuration options
see the example of client
or server on github.
|
| services.haven.settings | See https://github.com/bitvora/haven for documentation.
|
| services.grafana.settings | Grafana settings
|
| services.public-inbox.settings | Settings for the public-inbox config file.
|
| services.wiki-js.settings.db.db | Name of the database to use.
|
| services.zwave-js.settings | Configuration settings for the generated config file
|
| services.apache-kafka.settings | Kafka broker configuration
server.properties
|
| services.tor.settings.ORPort | See torrc manual.
|
| services.envoy.settings | Specify the configuration for Envoy in Nix.
|
| services.isso.settings | Configuration for isso
|
| services.goss.settings | The global options in config file in yaml format
|
| services.kubo.settings | Attrset of daemon configuration
|
| services.nats.settings | Declarative NATS configuration
|
| services.wiki-js.settings | Settings to configure wiki-js
|
| services.suricata.settings | Suricata settings
|
| services.nfs.settings | General configuration for NFS daemons and tools
|
| services.komga.settings | Komga configuration
|
| services.angrr.settings | Global configuration for angrr in TOML format.
|
| services.dunst.settings | Dunst configuration, see dunst(5)
|
| services.zrepl.settings | Configuration for zrepl
|
| services.pds.settings.PDS_PORT | Port to listen on
|
| services.mpd.settings.port | This setting is the TCP port that is desired for the daemon to get assigned
to.
|
| services.tor.settings.DirPort | See torrc manual.
|
| services.tor.settings.DNSPort | See torrc manual.
|
| services.tor.settings.PidFile | See torrc manual.
|
| services.forgejo.settings | Free-form settings written directly to the app.ini configfile file
|
| services.pds.settings | Environment variables to set for the service
|
| services.rsync.jobs.<name>.settings | Settings that should be passed to rsync via long options
|
| services.howdy.settings | Howdy configuration file
|
| services.gonic.settings | Configuration for Gonic, see https://github.com/sentriz/gonic#configuration-options for supported values.
|
| services.clatd.settings | Configuration of clatd
|
| services.plikd.settings | Configuration for plikd, see https://github.com/root-gg/plik/blob/master/server/plikd.cfg
for supported values.
|
| services.omnom.settings | Configuration options for the /etc/omnom/config.yml file.
|
| services.slskd.settings | Application configuration for slskd
|
| services.nipap.settings | Configuration options to set in /etc/nipap/nipap.conf.
|
| services.logind.settings.Login | Settings option for systemd-logind
|
| services.openssh.settings.Macs | Allowed MACs
Defaults to recommended settings from both
https://stribika.github.io/2015/01/04/secure-secure-shell.html
and
https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67
|
| services.inadyn.settings.custom | Settings for custom DNS providers.
|
| services.actual.settings | Server settings, refer to the documentation for available options
|
| services.umami.settings.BASE_PATH | Allows you to host Umami under a subdirectory
|
| services.nvme-rs.settings | Configuration for nvme-rs in TOML format
|
| services.thinkfan.settings | Thinkfan settings
|
| services.tor.settings.IPv6Exit | See torrc manual.
|
| services.tor.settings.ExtORPort | See torrc manual.
|
| services.tor.settings.GeoIPFile | See torrc manual.
|
| services.wiki-js.settings.port | TCP port the process should listen to.
|
| services.karma.settings | Karma dashboard configuration as nix attributes
|
| services.hatsu.settings | Configuration for Hatsu, see
|
| services.gitea.settings | Gitea configuration
|
| services.tuned.settings | Configuration for TuneD
|
| services.xmrig.settings | XMRig configuration
|
| services.acme-dns.settings.api.ip | IP to bind the HTTP API on.
|
| services.pretalx.settings | pretalx configuration as a Nix attribute set
|
| services.lokinet.settings | Configuration for Lokinet
|
| services.oink.settings.apiKey | API key to use when modifying DNS records.
|
| services.dolibarr.settings | Dolibarr settings, see https://github.com/Dolibarr/dolibarr/blob/develop/htdocs/conf/conf.php.example for details.
|
| services.mediamtx.settings | Settings for MediaMTX
|
| services.cross-seed.settingsFile | Path to a JSON file containing settings that will be merged with the
settings option
|
| services.wiki-js.settings.bindIP | IPs the service should listen to.
|
| services.acme-dns.settings.api.tls | TLS backend to use.
|
| services.pdns-recursor.settings | PowerDNS Recursor settings
|
| services.gatus.settings | Configuration for Gatus
|
| services.ulogd.settings | Configuration for ulogd
|
| services.pgscv.settings | Configuration for pgSCV, in YAML format
|
| services.tempo.settings | Specify the configuration for Tempo in Nix
|
| services.rimgo.settings.PORT | The port to use.
|
| services.umami.settings.PORT | The port to listen on.
|
| services.aria2.settings.dir | Directory to store downloaded files.
|
| services.canaille.settings | Settings for Canaille
|
| services.tor.settings.NATDPort | See torrc manual.
|
| services.crab-hole.settings | Crab-holes config
|
| services.wiki-js.settings.db.host | Hostname or socket-path to connect to.
|
| services.ente.api.settings.db.port | The database port
|
| services.ente.api.settings.db.host | The database host
|
| services.ente.api.settings.db.user | The database user
|
| services.ente.api.settings.db.name | The database name
|
| services.cockpit.settings | Settings for cockpit that will be saved in /etc/cockpit/cockpit.conf
|
| services.rauc.settings | Rauc configuration that will be converted to INI
|
| services.legit.settings | The primary legit configuration
|
| services.umami.settings | Additional configuration (environment variables) for Umami, see
https://umami.is/docs/environment-variables for supported values.
|
| services.stash.settings.port | The port that Stash should listen on.
|
| services.inadyn.settings | See inadyn.conf (5)
|
| services.mbpfan.settings | INI configuration for Mbpfan.
|
| services.omnom.settings.db.type | Database type.
|
| services.kanboard.settings | Customize the default settings, refer to https://github.com/kanboard/kanboard/blob/main/config.default.php
for details on supported values.
|
| services.dendrite.settings | Configuration for dendrite, see:
https://github.com/matrix-org/dendrite/blob/main/dendrite-sample.yaml
for available options with which to populate settings.
|
| services.pixelfed.settings | .env settings for Pixelfed
|
| services.tsidp.settings.port | Port to listen on (default: 443).
|
| services.tor.settings.DirCache | See torrc manual.
|
| services.tor.settings.GeoIPv6File | See torrc manual.
|
| services.stash.settings.host | The ip address that Stash should bind to.
|
| services.dex.settings | The available options can be found in
the example configuration
|
| services.cloud-init.settings | Structured cloud-init configuration.
|
| services.kismet.settings | Options for Kismet
|
| services.vector.settings | Specify the configuration for Vector in Nix.
|
| services.alice-lg.settings | alice-lg configuration, for configuration options see the example on github
|
| services.paisa.settings.dbFile | Filename of the Paisa database.
|
| services.nvme-rs.settings.email | Email notification configuration
|
| services.mympd.settings.ssl | Whether to enable listening on the SSL port
|
| services.sabnzbd.settings.ntfosd | NotifyOSD settings
|
| services.cgit.<name>.settings | cgit configuration, see cgitrc(5)
|
| services.uhub.<name>.settings | Configuration of uhub
|
| services.harmonia.settings | Settings to merge with the default configuration
|
| services.lemmy.settings.port | Port where lemmy should listen for incoming requests.
|
| services.kanidm.server.settings | Settings for Kanidm, see
the documentation
and example configuration
for possible values.
|
| services.kea.dhcp4.settings | Kea DHCP4 configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp4-srv.html.
|
| services.kea.dhcp6.settings | Kea DHCP6 configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp6-srv.html.
|
| services.atticd.settings | Structured configurations of atticd
|
| services.garage.settings | Garage configuration, see https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/ for reference.
|
| services.part-db.settings | Options for part-db configuration
|
| services.tor.settings.HidServAuth | See torrc manual.
|
| services.opengfw.settings.replay | PCAP replay settings.
|
| services.evcc.settings | evcc configuration as a Nix attribute set
|
| services.acme-dns.settings.api.port | Listen port for the HTTP API.
|
| services.godns.settings | Configuration for GoDNS
|
| services.sympa.settings | The sympa.conf configuration file as key value set
|
| security.agnos.settings | Settings
|
| services.qui.settings | qui configuration options
|
| services.pds.settings.PDS_DID_PLC_URL | URL of DID PLC directory
|
| services.slskd.settings.web.port | The HTTP listen port.
|
| services.nvme-rs.settings.email.to | Recipient email address
|
| services.kea.dhcp-ddns.settings | Kea DHCP-DDNS configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/ddns.html.
|
| services.hebbot.settings | Configuration for Hebbot, see, for examples:
|
| services.kavita.settings | Kavita configuration options, as configured in appsettings.json.
|
| services.gancio.settings | Configuration for Gancio, see https://gancio.org/install/config for supported values.
|
| services.dgraph.settings | Contents of the dgraph config
|
| services.rsyncd.settings | Configuration for rsyncd
|
| services.xray.settingsFile | The absolute path to the configuration file
|
| services.stash.settings.cache | Path to cache
|
| services.neard.settings | Neard INI-style configuration file as a Nix attribute set
|
| services.dsnet.settings.IP | The IPv4 address that the server will use on the network
|
| services.uhub.<name>.plugins.*.settings | Settings specific to this plugin.
|
| systemd.oomd.settings.OOM | Settings option for systemd-oomd
|
| services.paisa.settings.dataDir | Path to paisa data directory.
|
| services.tor.settings.ExitRelay | See torrc manual.
|
| services.tor.settings.SOCKSPort | See torrc manual.
|
| services.tor.settings.TransPort | See torrc manual.
|
| services.tor.settings.PerConnBWRate | See torrc manual.
|
| services.sunshine.settings | Settings to be rendered into the configuration file
|
| services.blocky.settings | Blocky configuration
|
| services.erigon.settings | Configuration for Erigon
Refer to https://github.com/ledgerwatch/erigon#usage for details on supported values.
|
| services.greetd.settings | greetd configuration (documentation)
as a Nix attribute set.
|
| services.gobgpd.settings | GoBGP configuration
|
| services.soft-serve.settings | The contents of the configuration file for soft-serve
|
| services.qdrant.settings | Configuration for Qdrant
Refer to https://github.com/qdrant/qdrant/blob/master/config/config.yaml for details on supported values.
|
| services.gerrit.settings | Gerrit configuration
|
| services.zeyple.settings | Zeyple configuration. refer to
https://github.com/infertux/zeyple/blob/master/zeyple/zeyple.conf.example
for details on supported values.
|
| services.aesmd.settings.proxy | HTTP network proxy.
|
| services.phpfpm.settings | PHP-FPM global directives
|
| services.gatus.settings.web.port | The TCP port to serve the Gatus service at.
|
| services.nfs.idmapd.settings | libnfsidmap configuration
|
| services.postfix.settings.main | The main.cf configuration file as key value set
|
| services.actual.settings.port | The port to listen on
|
| services.kavita.settings.Port | Port to bind to.
|
| services.mopidy.settings | The configuration that Mopidy should use
|
| services.strfry.settings | Configuration options to set for the Strfry service
|
| services.mchprs.settings | Configuration for MCHPRS via Config.toml
|
| services.zenohd.settings | Config options for zenoh.json5 configuration file
|
| services.dsnet.settings.IP6 | The IPv6 address that the server will use on the network
Leave this empty to let dsnet choose an address.
|
| services.zfs.zed.settings | ZFS Event Daemon /etc/zfs/zed.d/zed.rc content
See
zed(8)
for details on ZED and the scripts in /etc/zfs/zed.d to find the possible variables
|
| services.samba.settings | Configuration file for the Samba suite in ini format
|
| services.slskd.settings.rooms | Chat rooms to join on startup.
|
| services.tor.settings.AuthDirPinKeys | See torrc manual.
|
| services.cryptpad.settings | Cryptpad configuration settings
|
| services.omnom.settings.smtp.tls | Whether to enable Whether TLS encryption should be used..
|
| services.zwave-js-ui.settings | Extra environment variables passed to the zwave-js-ui process
|
| services.sftpgo.settings.smtp | SMTP configuration section.
|
| services.omnom.settings.smtp.host | SMTP server hostname.
|
| services.clight.settings | Additional configuration to extend clight.conf
|
| services.netbox.settings | Configuration options to set in configuration.py
|
| services.sftpgo.settings | The primary sftpgo configuration
|
| services.porn-vault.settings | Configuration for Porn-Vault
|
| services.pghero.settings | PgHero configuration
|
| services.paperless.settings | Extra paperless config options
|
| services.taler.settings | Global configuration options for the taler config file
|
| services.nostr-rs-relay.settings | See https://git.sr.ht/~gheartsfield/nostr-rs-relay/#configuration for documentation.
|
| services.renovate.settings | Renovate's global configuration
|
| services.pocket-id.settings | Environment variables to be passed
|
| services.omnom.settings.smtp.port | SMTP server port address.
|
| services.ananicy.settings | See https://github.com/Nefelim4ag/Ananicy/blob/master/ananicy.d/ananicy.conf
|
| services.radicle.settings | See https://app.radicle.xyz/nodes/seed.radicle.garden/rad:z3gqcJUoA1n9HaHKufZs5FCSGazv5/tree/radicle/src/node/config.rs#L275
|
| services.artalk.settings.port | Artalk server listen port
|
| services.artalk.settings.host | Artalk server listen host
|
| services.tsidp.settings.hostName | The hostname to use for the tsnet node.
|
| services.tor.settings.DirPolicy | See torrc manual.
|
| services.rkvm.server.settings | Structured server daemon configuration
|
| services.rkvm.client.settings | Structured client daemon configuration
|
| programs.nncp.settings | NNCP configuration, see
http://www.nncpgo.org/Configuration.html
|
| services.chhoto-url.settings | Configuration of Chhoto URL
|
| services.doh-server.settings | Configuration of doh-server in toml
|
| services.pihole-ftl.settings | Configuration options for pihole.toml
|
| services.wiki-js.settings.logLevel | Define how much detail is supposed to be logged at runtime.
|
| services.homed.settings.Home | Options for systemd-homed
|
| services.aria2.settings.conf-path | Configuration file path.
|
| services.gitea.settings.log.LEVEL | General log level.
|
| services.nvme-rs.settings.email.from | Sender email address
|
| services.nezha-agent.settings.gpu | Enable GPU monitoring.
|
| services.kea.ctrl-agent.settings | Kea Control Agent configuration as an attribute set, see https://kea.readthedocs.io/en/kea-3.0.2/arm/agent.html.
|
| services.opengfw.settings.workers | Worker settings.
|
| services.movim.h2o.settings | Attrset to be transformed into YAML for host config
|
| services.cross-seed.settings.port | Port the cross-seed daemon listens on.
|
| services.freeciv.settings | Parameters of freeciv-server.
|
| services.openssh.settings | Configuration for sshd_config(5).
|
| services.mealie.settings | Configuration of the Mealie service
|
| services.veilid.settings | Build veilid-server.conf with nix expression
|
| services.go2rtc.settings | go2rtc configuration as a Nix attribute set
|
| services.chhoto-url.settings.port | The port to listen on.
|
| services.mympd.settings | Manages the configuration files declaratively
|
| services.listmonk.settings | Static settings set in the config.toml, see https://github.com/knadh/listmonk/blob/master/config.toml.sample for details
|
| services.dwm-status.settings | Config options for dwm-status, see https://github.com/Gerschtli/dwm-status#configuration
for available options.
|
| services.oink.settings.ttl | The TTL ("Time to Live") value to set for your DNS records
|
| services.gancio.settings.db.host | Connection string for the PostgreSQL database
|
| services.omnom.settings.app.debug | Whether to enable debug mode.
|
| services.tor.settings.HidServAuth.*.auth | Authentication cookie.
|
| services.nezha-agent.settings.tls | Enable SSL/TLS encryption.
|
| services.tor.settings.PerConnBWBurst | See torrc manual.
|
| services.mchprs.settings.port | Port for the server
|
| services.mchprs.settings.motd | Message of the day
|
| services.llama-swap.settings | llama-swap configuration
|
| services.litellm.settings | Configuration for LiteLLM
|
| services.kubo.settings.Mounts.MFS | Where to mount the MFS namespace to
|
| services.reaction.settings | Configuration for reaction
|
| services.ente.api.settings | Museum yaml configuration
|
| services.legit.settings.meta.title | Website title.
|
| services.misskey.settings.db.db | The database name.
|
| services.glance.settings | Configuration written to a yaml file that is read by glance
|
| services.artalk.settings | The artalk configuration
|
| services.knot.settingsFile | As alternative to settings, you can provide whole configuration
directly in the almost-YAML format of Knot DNS
|
| services.schleuder.settings | Settings for schleuder.yml
|
| services.molly-brown.settings | molly-brown configuration
|
| services.biboumi.settings | See biboumi 9.0
for documentation.
|
| services.waagent.settings | The waagent.conf configuration, see https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/agent-linux for documentation.
|
| services.zipline.settings | Configuration of Zipline
|
| services.doh-server.settings.path | HTTP path for resolve application
|
| services.tor.settings.ExitPolicy | See torrc manual.
|
| services.pocket-id.settings.APP_URL | The URL where you will access the app.
|
| services.ente.api.settings.apps.cast | Set this to the URL where your cast page is running
|
| services.sftpgo.settings.smtp.from | From address.
|
| services.invidious.settings | The settings Invidious should use
|
| services.nominatim.settings | Nominatim configuration settings
|
| services.postfix.settings.master | The master.cf configuration file as an attribute set of service
defitions
|
| services.mpd.settings.db_file | The path to MPD's database.
|
| services.tsidp.settings.localPort | Listen on localhost:.
|
| services.paisa.settings | Paisa configuration
|
| services.nzbget.settings | NZBGet configuration, passed via command line using switch -o
|
| services.sing-box.settings | The sing-box configuration, see https://sing-box.sagernet.org/configuration/ for documentation
|
| services.openbao.settings.ui | Whether to enable the OpenBao web UI.
|
| services.sftpgo.settings.smtp.user | SMTP username.
|
| services.tsidp.settings.logLevel | Set logging level: debug, info, warn, error.
|
| services.uptime-kuma.settings | Additional configuration for Uptime Kuma, see
https://github.com/louislam/uptime-kuma/wiki/Environment-Variables
for supported values.
|
| services.gitea.settings.log.ROOT_PATH | Root path for log files.
|
| services.grocy.phpfpm.settings | Options for grocy's PHPFPM pool.
|
| services.tor.settings.Address | See torrc manual.
|
| services.tor.settings.ClientUseIPv6 | See torrc manual.
|
| services.tor.settings.HSLayer3Nodes | See torrc manual.
|
| services.tor.settings.Sandbox | See torrc manual.
|
| services.tor.settings.HSLayer2Nodes | See torrc manual.
|
| services.tor.settings.ClientUseIPv4 | See torrc manual.
|
| services.glpiAgent.settings | GLPI Agent configuration options
|
| services.autobrr.settings | Autobrr configuration options
|
| services.klipper.settings | Configuration for Klipper
|
| services.readeck.settings | Additional configuration for Readeck, see
https://readeck.org/en/docs/configuration
for supported values.
|
| services.redmine.settings | Redmine configuration (configuration.yml)
|
| services.misskey.settings | Configuration for Misskey, see
example.yml
for all supported options.
|
| services.zitadel.settings | Contents of the runtime configuration file
|
| services.vikunja.settings | Vikunja configuration
|
| services.grafana-to-ntfy.settings.bauthPass | The path to the password you will use in the Grafana webhook settings.
|
| services.openssh.settings.Ciphers | Allowed ciphers
Defaults to recommended settings from both
https://stribika.github.io/2015/01/04/secure-secure-shell.html
and
https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67
|
| services.kubo.settings.Mounts.IPNS | Where to mount the IPNS namespace to
|
| services.kubo.settings.Mounts.IPFS | Where to mount the IPFS namespace to
|
| services.sftpgo.settings.smtp.port | Port of the SMTP Server.
|
| services.displayManager.ly.settings | Extra settings merged in and overwriting defaults in config.ini.
|
| services.wiki-js.settings.db.type | Database driver to use for persistence
|
| services.tuned.settings.daemon | Whether to enable the use of a daemon for TuneD.
|
| services.stash.settings.stash.*.path | location of your media files
|
| services.pds.settings.PDS_BSKY_APP_VIEW_DID | DID of bsky frontend
|
| services.freeciv.settings.read | Startup script.
|
| services.sslh.settings.timeout | Timeout in seconds.
|
| services.nezha-agent.settings | Generate to config.json as a Nix attribute set
|
| services.corteza.settings | Configuration for Corteza, will be passed as environment variables
|
| services.orthanc.settings | Configuration written to a json file that is read by orthanc
|
| services.zeronet.settings | zeronet.conf configuration
|
| services.phpfpm.pools.<name>.settings | PHP-FPM pool directives
|
| services.tor.settings.HidServAuth.*.onion | Onion address.
|
| services.tor.settings.DirPortFrontPage | See torrc manual.
|
| services.gns3-server.settings | The global options in config file in ini format
|
| services.hound.settings | The full configuration of the Hound daemon
|
| services.memos.settings | The environment variables to configure Memos.
At time of writing, there is no clear documentation about possible values
|
| services.glance.settings.pages | List of pages to be present on the dashboard
|
| services.go-httpbin.settings | Configuration of go-httpbin
|
| services.go-csp-collector.settings | Settings for go-csp-collector
|
| services.dashy.settings | Settings serialized into user-data/conf.yml before build
|
| services.pds.settings.PDS_BSKY_APP_VIEW_URL | URL of bsky frontend
|
| services.zitadel.settings.Port | The port that ZITADEL listens on.
|
| services.sharkey.settings.id | The ID generation method for Sharkey to use
|
| services.legit.settings.repo.scanPath | Directory where legit will scan for repositories.
|
| services.amule.settings.eMule.Port | TCP port for eD2k connections
|
| services.logrotate.settings.<name>.global | Whether this setting is a global option or not: set to have these
settings apply to all files settings with a higher priority.
|
| services.goeland.settings | Configuration of goeland
|
| services.corerad.settings | Configuration for CoreRAD, see https://github.com/mdlayher/corerad/blob/main/internal/config/reference.toml
for supported values
|
| services.merecat.settings | Merecat configuration
|
| services.sharkey.settings | Configuration options for Sharkey
|
| services.sabnzbd.settings | The sabnzbd configuration (see also
sabnzbd's wiki
for extra documentation)
|
| services.misskey.settings.db.port | The PostgreSQL port.
|
| services.misskey.settings.db.host | The PostgreSQL host.
|
| programs.rust-motd.settings | Settings on what to generate
|
| services.pds.settings.LOG_ENABLED | Enable logging
|
| services.go-httpbin.settings.PORT | The port to listen on.
|
| services.go-httpbin.settings.HOST | The host to listen on.
|
| services.kanidm.unix.settings | Configure Kanidm unix daemon
|
| services.rkvm.server.settings.key | TLS key path.
This should be generated with rkvm-certificate-gen.
|
| services.freeciv.settings.auth | Whether to enable server authentication.
|
| services.dwm-status.settings.order | List of enabled features in order.
|
| services.freeciv.settings.port | Listen for clients on given port
|
| services.openssh.settings.UsePAM | Whether to enable PAM authentication.
|
| services.tor.settings.TransProxyType | See torrc manual.
|
| services.misskey.settings.port | The port your Misskey server should listen on.
|
| services.tor.settings.SocksPolicy | See torrc manual.
|
| services.tor.settings.BridgeRelay | See torrc manual.
|
| services.tor.settings.LongLivedPorts | See torrc manual.
|
| services.sharkey.settings.port | The port that Sharkey will listen on.
|
| services.xonotic.settings.port | The port Xonotic will listen on.
|
| services.stash.settings.stash | Add directories containing your adult videos and images
|
| services.pretix.settings.mail.host | Hostname of the SMTP server use for mail delivery.
|
| services.pretix.settings.mail.port | Port of the SMTP server to use for mail delivery.
|
| services.misskey.settings.id | The ID generation method to use
|
| services.xonotic.settings | Generates the server.cfg file
|
| services.oncall.settings.db.conn.str | Database connection scheme
|
| services.amule.settings.eMule.TempDir | Directory where aMule stores incomplete downloads (.part/.part.met files).
|
| services.mysql.settings | MySQL configuration
|
| services.oncall.settings | Extra configuration options to append or override
|
| services.legit.settings.server.host | Host address.
|
| services.legit.settings.server.name | Server name.
|
| services.legit.settings.server.port | Legit port.
|
| services.legit.settings.repo.ignore | Repositories to ignore.
|
| services.doh-server.settings.tries | Number of tries if upstream DNS fails
|
| services.automx2.settings | Bootstrap json to populate database
|
| services.pretix.settings.mail.from | E-Mail address used in the FROM header of outgoing mails.
|
| services.maubot.settings.server | Listener config
|
| services.homebox.settings | The homebox configuration as environment variables
|
| services.bonsaid.settings | State transition definitions
|
| services.unbound.settings | Declarative Unbound configuration
See the unbound.conf(5) manpage for a list of
available options.
|
| services.osquery.settings | Configuration to be written to the osqueryd JSON configuration file
|
| services.misskey.settings.db.user | The user used for database authentication.
|
| services.opengfw.settings.io.sndBuf | Netlink send buffer size.
|
| services.misskey.settings.db.pass | The password used for database authentication.
|
| services.opengfw.settings.io.rcvBuf | Netlink receive buffer size.
|
| services.oink.settings.secretApiKey | Secret API key to use when modifying DNS records.
|
| services.haste-server.settings | Configuration for haste-server
|
| services.zabbixProxy.settings | Zabbix Proxy configuration
|
| services.zabbixAgent.settings | Zabbix Agent configuration
|
| services.tor.settings.HTTPTunnelPort | See torrc manual.
|
| services.tor.settings.CookieAuthFile | See torrc manual.
|
| services.tor.settings.AuthDirListBadExits | See torrc manual.
|
| services.displayManager.sddm.settings | Extra settings merged in and overwriting defaults in sddm.conf.
|
| services.homer.settings | Settings serialized into config.yml before build
|
| services.opengfw.settingsFile | Path to file containing OpenGFW settings.
|
| services.peertube.settings | Configuration for peertube.
|
| services.quickwit.settings | Quickwit configuration.
|
| services.warpgate.settings | Warpgate configuration.
|
| services.step-ca.settings | Settings that go into ca.json
|
| services.legit.settings.repo.readme | Readme files to look for.
|
| services.karma.settings.listen.port | HTTP port to listen on.
|
| services.nipap.settings.nipapd.port | Port to bind nipapd to.
|
| services.inadyn.settings.provider | Settings for DDNS providers built-in to inadyn
|
| services.livekit.settings.port | Main TCP port for RoomService and RTC endpoint.
|
| services.h2o.hosts.<name>.settings | Attrset to be transformed into YAML for host config
|
| services.mpd.settings | Configuration for MPD
|
| services.vmalert.settings | vmalert configuration, passed via command line flags
|
| services.grafana-to-ntfy.settings.bauthUser | The user that you will authenticate with in the Grafana webhook settings
|
| services.lasuite-meet.livekit.settings | Settings to pass to the livekit server
|
| services.kimai.sites.<name>.settings | Structural Kimai's local.yaml configuration
|
| services.lidarr.settings | Attribute set of arbitrary config options
|
| services.cross-seed.settings | Configuration options for cross-seed
|
| services.sonarr.settings | Attribute set of arbitrary config options
|
| services.radarr.settings | Attribute set of arbitrary config options
|
| services.sharkey.settings.url | The full URL that the Sharkey instance will be publically accessible on
|
| services.evremap.settings.remap | List of remappings.
|
| services.rimgo.settings.ADDRESS | The address to listen on.
|
| services.opendkim.settings | Additional opendkim configuration
|
| services.packagekit.settings | Additional settings passed straight through to PackageKit.conf
|
| services.komga.settings.server.port | The port that Komga will listen on.
|
| services.legit.settings.dirs.static | Directories where static files are located.
|
| services.omnom.settings.smtp.sender | Omnom sender e-mail.
|
| services.biboumi.settings.port | The TCP port to use to connect to the local XMPP component.
|
| services.tsidp.settings.enableSts | Enable OAuth token exchange using RFC 8693.
|
| services.scrutiny.settings | Scrutiny settings to be rendered into the configuration file
|
| services.tor.settings.ControlPort | See torrc manual.
|
| services.tor.settings.FetchDirInfoEarly | See torrc manual.
|
| services.tor.settings.ContactInfo | See torrc manual.
|
| services.udisks2.settings | Options passed to udisksd
|
| services.patroni.settings | The primary patroni configuration
|
| services.livekit.settings | LiveKit configuration file expressed in nix
|
| services.sonic-server.settings | Sonic Server configuration options
|
| services.grocy.settings.culture | Display language of the frontend.
|
| services.aria2.settings.enable-rpc | Enable JSON-RPC/XML-RPC server.
|
| services.lxd-image-server.settings | Configuration for lxd-image-server
|
| services.spacecookie.settings | Settings for spacecookie
|
| services.lokinet.settings.dns.bind | Address to bind to for handling DNS requests.
|
| services.sftpgo.settings.smtp.host | Location of SMTP email server
|
| services.influxdb.settings | Extra configuration options for influxdb
|
| services.crowdsec.settings | Set of various configuration attributes
|
| services.openldap.settings | Configuration for OpenLDAP, in OLC format
|
| services.minidlna.settings | Configuration for minidlna.conf(5).
|
| services.grafana.settings.smtp.host | Host to connect to.
|
| services.inadyn.settings.allow-ipv6 | Whether to get IPv6 addresses from interfaces.
|
| services.tsidp.settings.debugTsnet | For development
|
| services.wiki-js.settings.offline | Disable latest file updates and enable
sideloading.
|
| services.freeciv.settings.debug | Set debug log level.
|
| services.tor.settings.V3AuthUseLegacyKey | See torrc manual.
|
| services.pretalx.settings.site.url | The base URI below which your pretalx instance will be reachable.
|
| services.opengfw.settings.io.rst | Set to true if you want to send RST for blocked TCP connections, needs local = false.
|
| services.traccar.settingsFile | File used as configuration for traccar
|
| services.hedgedoc.settings | HedgeDoc configuration, see
https://docs.hedgedoc.org/configuration/
for documentation.
|
| services.olivetin.settings | Configuration of OliveTin
|
| services.routedns.settings | Configuration for RouteDNS, see https://github.com/folbricht/routedns/blob/master/doc/configuration.md
for more information.
|
| services.amule.settings.WebServer.Port | Web server port
|
| services.grafana.settings.smtp.user | User used for authentication.
|
| services.misskey.settings.db.extra | Extra connection options.
|
| services.frigate.settings.mqtt.host | MQTT server hostname
|
| services.kanidm.client.settings.uri | Address of the Kanidm server.
|
| services.polaris.settings | Contents for the TOML Polaris config, applied each start
|
| services.chhoto-url.settings.db_url | The path of the sqlite database.
|
| services.apache-kafka.settings."log.dirs" | Log file directories.
|
| services.wg-access-server.settings | See https://www.freie-netze.org/wg-access-server/2-configuration/ for possible options
|
| services.pdns-recursor.yaml-settings | PowerDNS Recursor settings
|
| services.bonsaid.settings.*.type | Type of transition
|
| services.bluesky-pds.settings.PDS_PORT | Port to listen on
|
| services.nezha-agent.settings.server | Address to the dashboard.
|
| services.zipline.settings.CORE_PORT | The port to listen on.
|
| services.crowdsec.settings.general | Settings for the main CrowdSec configuration file
|
| services.go2rtc.settings.ffmpeg.bin | The ffmpeg package to use for transcoding.
|
| services.ergochat.settings | Ergo IRC daemon configuration file.
https://raw.githubusercontent.com/ergochat/ergo/master/default.yaml
|
| services.spotifyd.settings | Configuration for Spotifyd
|
| services.netatalk.settings | Configuration for Netatalk
|
| services.clamav.daemon.settings | ClamAV configuration
|
| services.cross-seed.settings.linkDirs | List of directories where cross-seed will create links
|
| services.doh-server.settings.listen | HTTP listen address and port
|
| services.tor.settings.DisableAllSwap | See torrc manual.
|
| services.tor.settings.Nickname | See torrc manual.
|
| services.forgejo.settings.log.LEVEL | General log level.
|
| services.pretix.settings.tools.pdftk | Path to the pdftk executable.
|
| services.nipap.settings.nipapd.debug | Enable debug logging.
|
| xdg.portal.wlr.settings | Configuration for xdg-desktop-portal-wlr
|
| services.misskey.settings.redis | ioredis options
|
| services.sslh.settings.numeric | Whether to disable reverse DNS lookups, thus keeping IP
address literals in the log.
|
| services.hickory-dns.settings.zones | List of zones to serve.
|
| services.zitadel.settings.TLS.KeyPath | Path to the TLS certificate private key.
|
| services.peroxide.settings | Configuration for peroxide
|
| services.fediwall.settings | Fediwall configuration
|
| services.ferretdb.settings | Additional configuration for FerretDB, see
https://docs.ferretdb.io/configuration/flags/
for supported values.
|
| services.actual.settings.userFiles | The server will put all the budget files in this directory as binary blobs.
|
| services.lidarr.settings.server.port | Port Number
|
| services.maubot.settings.server.port | The port to listen on
|
| services.radarr.settings.server.port | Port Number
|
| services.sonarr.settings.server.port | Port Number
|
| services.rathole.settings | Rathole configuration, for options reference
see the example on GitHub
|
| services.frigate.settings | Frigate configuration as a nix attribute set
|
| services.fediwall.settings.tags | Tags to follow
|
| services.hedgedoc.settings.port | Port to listen on.
|
| services.hedgedoc.settings.host | Address to listen on.
|
| services.lasuite-meet.settings.DB_NAME | Name of the database
|
| services.lasuite-docs.settings.DB_NAME | Name of the database
|
| services.lasuite-docs.settings.DB_USER | User of the database
|
| services.lasuite-meet.settings.DB_HOST | Host of the database
|
| services.lasuite-meet.settings.DB_USER | User of the database
|
| services.lasuite-docs.settings.DB_HOST | Host of the database
|
| services.bluesky-pds.settings | Environment variables to set for the service
|
| services.resolved.settings.Resolve | Settings option for systemd-resolved
|
| services.freeciv.settings.exit-on-end | Whether to enable exit instead of restarting when a game ends.
|
| services.auto-cpufreq.settings | Configuration for auto-cpufreq
|
| services.sabnzbd.settings.misc.port | Port for the Web UI to listen on for incoming connections.
|
| services.pretix.settings.pretix.url | The installation’s full URL, without a trailing slash.
|
| services.sabnzbd.settings.misc.host | Address for the Web UI to listen on for incoming connections.
|
| services.tor.settings.ClientAutoIPv6ORPort | See torrc manual.
|
| services.dsnet.settings | The settings to use for dsnet
|
| services.gitlab-runner.settings | Global gitlab-runner configuration
|
| services.libeufin.settings | Global configuration options for the libeufin bank system config file.
|
| services.temporal.settings | Temporal configuration
|
| services.sshwifty.settings | Configuration for Sshwifty
|
| services.zabbixServer.settings | Zabbix Server configuration
|
| services.glance.settings.server.port | Glance port to listen on
|
| services.glance.settings.server.host | Glance bind address
|
| services.legit.settings.repo.mainBranch | Main branch to look for.
|
| services.zitadel.settings.TLS.CertPath | Path to the TLS certificate.
|
| services.gokapi.settingsFile | Path to config file to parse and append to settings
|
| services.crowdsec.settings.capi | CAPI Configuration attributes
|
| services.crowdsec.settings.lapi | LAPI Configuration attributes
|
| services.gitea.settings.server.ROOT_URL | Full public URL of gitea server.
|
| services.amule.settings.eMule.UDPPort | UDP port for eD2k traffic (searches, source exchange) and all Kad network communication
|
| services.misskey.settings.redis.host | The Redis host.
|
| services.omnom.settings.storage.type | Storage type.
|
| services.misskey.settings.redis.port | The Redis port.
|
| services.go2rtc.settings.api.listen | API listen address, conforming to a Go address string.
|
| services.pds.settings.PDS_CRAWLERS | URL of crawlers
|
| services.castopod.settings | Environment variables used for Castopod
|
| services.radicale.settings | Configuration for Radicale
|
| services.firefly-iii.settings.DB_PORT | The port your database is listening at. sqlite does not require
this value to be filled.
|
| services.tor.settings.ClientOnionAuthDir | See torrc manual.
|
| services.quickwit.settings.rest | Rest server configuration for Quickwit
|
| services.immich-kiosk.settings | Configuration for immich-kiosk
|
| services.prosody-filer.settings | Configuration for Prosody Filer
|
| services.lasuite-docs.settings.DATA_DIR | Path to the data directory
|
| services.pangolin.settings | Additional attributes to be merged with the configuration options and written to Pangolin's config.yml file.
|
| services.pinnwand.settings | Your pinnwand.toml as a Nix attribute set
|
| services.postsrsd.settings | Configuration options for the postsrsd.conf file
|
| services.aesmd.settings.proxyType | Type of proxy to use
|
| services.misskey.settings.url | The final user-facing URL
|
| services.inadyn.settings.custom.<name>.include | File to include additional settings for this provider from.
|
| services.cross-seed.settings.outputDir | Directory where cross-seed will place torrent files it finds.
|
| services.hockeypuck.settings | Configuration file for hockeypuck, here you can override
certain settings (loglevel and
openpgp.db.dsn) by just setting those values
|
| services.hatsu.settings.HATSU_DOMAIN | The domain name of your instance (eg 'hatsu.local').
|
| services.gemstash.settings.bind | Host and port combination for the server to listen on.
|
| services.suricata.settings.vars | Variables to be used within the suricata rules.
|
| services.oink.settings.interval | Seconds to wait before sending another request.
|
| services.suricata.settings.pcap | Cross platform libpcap capture support.
|
| services.forgejo.settings.log.ROOT_PATH | Root path for log files.
|
| power.ups.upsmon.settings | Additional settings to add to upsmon.conf.
|
| services.firefly-iii.settings.APP_ENV | The app environment
|
| services.opengfw.settings.io.local | Set to false if you want to run OpenGFW on FORWARD chain. (e.g. on a router)
|
| services.immich.settings | Configuration for Immich
|
| services.readarr.settings | Attribute set of arbitrary config options
|
| services.dnsmasq.settings.server | The DNS servers which dnsmasq should query.
|
| services.grafana-to-ntfy.settings.ntfyUrl | The URL to the ntfy-sh topic.
|
| services.gancio.settings.baseurl | The full URL under which the server is reachable.
|
| services.tor.settings.DisableOOSCheck | See torrc manual.
|
| services.moosefs.master.settings | Master configuration options (mfsmaster.cfg).
|
| services.gancio.settings.db.storage | Location for the SQLite database.
|
| services.gancio.settings.db.dialect | The database dialect to use
|
| services.opengfw.settings.io.queueSize | IO queue size.
|
| services.webdav-server-rs.settings | Attrset that is converted and passed as config file
|
| services.scion.scion-router.settings | scion-router configuration
|
| services.scion.scion-daemon.settings | scion-daemon configuration
|
| services.rkvm.server.settings.listen | An internet socket address to listen on, either IPv4 or IPv6.
|
| services.tor.relay.onionServices.<name>.settings | Settings of the onion service
|
| services.froide-govplan.settings | Configuration options to set in extra_settings.py.
|
| services.pds.settings.PDS_HOSTNAME | Instance hostname (base domain name)
|
| services.misskey.settings.socket | The UNIX socket your Misskey server should listen on.
|
| services.paisa.settings.journalFile | Filename of the main journal / ledger file.
|
| services.pocket-id.settings.TRUST_PROXY | Whether the app is behind a reverse proxy.
|
| services.pdns-recursor.old-settings | Older PowerDNS Recursor settings
|
| services.aria2.settings.listen-port | Set UDP listening port range used by DHT(IPv4, IPv6) and UDP tracker.
|
| services.microbin.settings | Additional configuration for MicroBin, see
https://microbin.eu/docs/installation-and-configuration/configuration/
for supported values
|
| services.wastebin.settings | Additional configuration for wastebin, see
https://github.com/matze/wastebin#usage for supported values
|
| services.nvme-rs.settings.email.use_tls | Use TLS for SMTP connection
|
| programs.yazi.settings | Configuration included in $YAZI_CONFIG_HOME.
|
| services.doh-server.settings.timeout | Upstream timeout
|
| services.doh-server.settings.verbose | Enable logging
|
| services.umami.settings.HOSTNAME | The address to listen on.
|
| services.gitea.settings.server.HTTP_PORT | Listen port
|
| services.buffyboard.settings | Settings to include in /etc/buffyboard.conf
|
| services.radicle.ci.broker.settings.db | Database file path.
|
| services.tor.settings.ExtORPortCookieAuthFile | See torrc manual.
|
| services.tor.settings.AuthDirTestEd25519LinkKeys | See torrc manual.
|
| services.gitlab.pages.settings.pages-root | The directory where pages are stored.
|
| services.gitea.settings.server.DOMAIN | Domain name of your server.
|
| services.lasuite-docs.settings | Configuration options of docs
|
| services.kanidm.client.settings | Configure Kanidm clients, needed for the PAM daemon
|
| services.rkvm.client.settings.server | An RKVM server's internet socket address, either IPv4 or IPv6.
|
| services.kanidm.server.settings.role | The role of this server
|
| services.mediagoblin.settings | Settings which are written into mediagoblin.ini.
|
| services.freeciv.settings.Guests | Whether to enable guests to login if auth is enabled.
|
| services.saunafs.master.settings | Contents of config file (sfsmaster.cfg(5)).
|
| services.c2fmzq-server.settings | Configuration for c2FmZQ-server passed as CLI arguments
|
| services.teleport.settings | Contents of the teleport.yaml config file
|
| services.warpgate.settings.http.key | Path to HTTPS listener private key.
|
| services.borgmatic.settings | See https://torsion.org/borgmatic/docs/reference/configuration/
|
| services.bluesky-pds.settings.PDS_DID_PLC_URL | URL of DID PLC directory
|
| services.openldap.settings.attrs | Attributes of the parent entry.
|
| services.stash.settings.database | Path to the SQLite database
|
| services.vmalert.settings.rule | Path to the files with alerting and/or recording rules.
Consider using the services.vmalert.rules option as a convenient alternative for declaring rules
directly in the nix language.
|
| services.webdav.settings | Attrset that is converted and passed as config file
|
| services.minidlna.settings.port | Port number for HTTP traffic (descriptions, SOAP, media transfer).
|
| services.gitea.settings.server.HTTP_ADDR | Listen address
|
| services.nipap.settings.nipapd.listen | IP address to bind nipapd to.
|
| programs.schroot.settings | Schroot configuration settings
|
| services.clamav.updater.settings | freshclam configuration
|
| services.warpgate.settings.ssh.keys | Path to store SSH host & client keys.
|
| services.dnsproxy.settings | Contents of the config.yaml config file
|
| services.stalwart.settings | Configuration options for the Stalwart server
|
| services.ntfy-sh.settings.base-url | Public facing base URL of the service
This setting is required for any of the following features:
- attachments (to return a download URL)
- e-mail sending (for the topic URL in the email footer)
- iOS push notifications for self-hosted servers
(to calculate the Firebase poll_request topic)
- Matrix Push Gateway (to validate that the pushkey is correct)
|
| services.sourcehut.settings."meta.sr.ht::settings".user-invites | How many invites each user is issued upon registration
(only applicable if open registration is disabled).
|
| services.pocket-id.settings.PUBLIC_APP_URL | The URL where you will access the app.
|
| services.tor.settings.FetchDirInfoExtraEarly | See torrc manual.
|
| services.tor.settings.ControlSocket | See torrc manual.
|
| services.sourcehut.settings | The configuration for the sourcehut network.
|
| services.bitmagnet.settings | Bitmagnet configuration (https://bitmagnet.io/setup/configuration.html).
|
| services.tinyproxy.settings | Configuration for tinyproxy.
|
| services.anubis.defaultOptions.policy.settings | Additional policy settings merged into the policy file
|
| services.sunshine.settings.port | Base port -- others used are offset from this one, see https://docs.lizardbyte.dev/projects/sunshine/en/latest/about/advanced_usage.html#port for details.
|
| services.dsnet.settings.Network | The IPv4 network that the server will use to allocate IPs on the network
|
| programs.bat.settings | Parameters to be written to the system-wide bat configuration file.
|
| services.immich-kiosk.settings.kiosk.port | Port on which immich-kiosk will listen.
|
| services.suricata.settings.run-as.user | Run Suricata with a specific user-id.
|
| services.oncall.settings.db.conn.kwargs.host | Database host.
|
| services.oncall.settings.db.conn.kwargs.user | Database user.
|
| services.lasuite-meet.settings | Configuration options of meet
|
| services.transfer-sh.settings | Additional configuration for transfer-sh, see
https://github.com/dutchcoders/transfer.sh#usage-1
for supported values
|
| services.lasuite-docs.settings.REDIS_URL | URL of the redis backend
|
| services.lasuite-meet.settings.REDIS_URL | URL of the redis backend
|
| services.nomad.settings | Configuration for Nomad
|
| services.actual.settings.dataDir | Directory under which Actual runs and saves its data
|
| services.readarr.settings.server.port | Port Number
|
| services.tlsrpt.fetcher.settings | Flags from tlsrpt-fetcher(1) as key-value pairs.
|
| services.tlsrpt.reportd.settings | Flags from tlsrpt-reportd(1) as key-value pairs.
|
| services.sharkey.settings.socket | If specified, creates a UNIX socket at the given path that Sharkey listens on.
|
| services.openssh.settings.PrintMotd | Whether to enable printing /etc/motd when a user logs in interactively.
|
| services.radicle.ci.broker.settings | Configuration of radicle-ci-broker
|
| services.librenms.settings | Attrset of the LibreNMS configuration
|
| services.gemstash.settings | Configuration for Gemstash
|
| services.aria2.settings.save-session | Save error/unfinished downloads to FILE on exit.
|
| services.pds.settings.PDS_BLOB_UPLOAD_LIMIT | Size limit of uploaded blobs in bytes
|
| services.lemmy.settings.hostname | The domain name of your instance (eg 'lemmy.ml').
|
| services.grocy.settings.currency | ISO 4217 code for the currency to display.
|
| services.stash.settings.no_proxy | A list of domains for which the proxy must not be used
|
| services.cross-seed.settings.dataDirs | Paths to be searched for matching data
|
| services.freeciv.settings.saves | Save games to given directory,
a sub-directory named after the starting date of the service
will me inserted to preserve older saves.
|
| services.listmonk.database.settings | Dynamic settings in the PostgreSQL database, set by a SQL script, see https://github.com/knadh/listmonk/blob/master/schema.sql#L177-L230 for details.
|
| services.firefox-syncserver.settings | Settings for the sync server
|
| services.dokuwiki.sites.<name>.settings | Structural DokuWiki configuration
|
| services.inadyn.settings.custom.<name>.ssl | Whether to use HTTPS for this DDNS provider.
|
| programs.atop.settings | Parameters to be written to /etc/atoprc.
|
| services.filebrowser.settings | Settings for FileBrowser
|
| services.fediwall.settings.hideBots | Hide posts from bot accounts
|
| services.cryptpad.settings.httpPort | Port on which the Node.js server should listen
|
| services.scrutiny.settings.log.level | Log level for Scrutiny.
|
| services.dsnet.settings.Network6 | The IPv6 network that the server will use to allocate IPs on the
network
|
| services.firefly-iii.settings | Options for firefly-iii configuration
|
| services.lldap.settings.http_url | The public URL of the server, for password reset links.
|
| services.glitchtip.settings | Configuration of GlitchTip
|
| services.supergfxd.settings | The content of /etc/supergfxd.conf
|
| services.rosenpass.settings | Configuration for Rosenpass, see https://rosenpass.eu/ for further information.
|
| services.mackerel-agent.settings | Options for mackerel-agent.conf
|
| services.manticore.settings | Configuration for Manticoresearch
|
| services.mosquitto.settings | Global configuration options for the mosquitto broker.
|
| services.cryptpad.settings.logLevel | Controls log level
|
| services.snips-sh.settings | The configuration of snips-sh is done through environment variables,
therefore you must use upper snake case (e.g. SNIPS_HTTP_INTERNAL)
|
| services.keycloak.settings.http-host | On which address Keycloak should accept new connections.
|
| services.maubot.settings.logging | Python logging configuration
|
| services.dolibarr.h2o.settings | Attrset to be transformed into YAML for host config
|
| services.pomerium.settings | The contents of Pomerium's config.yaml, in Nix expressions
|
| services.caddy.settings | Structured configuration for Caddy to generate a Caddy JSON configuration file
|
| services.etebase-server.settings | Configuration for etebase-server
|
| services.redis.servers.<name>.settings | Redis configuration
|
| services.matrix-tuwunel.settings | Generates the tuwunel.toml configuration file
|
| services.biboumi.settings.admin | The bare JID of the gateway administrator
|
| services.angrr.settings.owned-only | Only monitors owned symbolic link target of GC roots.
- "auto": behaves like true for normal users, false for root.
- "true": only monitor GC roots owned by the current user.
- "false": monitor all GC roots.
|
| services.aria2.settings.rpc-listen-port | Specify a port number for JSON-RPC/XML-RPC server to listen to
|
| services.immich-public-proxy.settings | Configuration for IPP
|
| services.swapspace.settings | Config file for swapspace
|
| services.navidrome.settings | Configuration for Navidrome, see https://www.navidrome.org/docs/usage/configuration-options/ for supported values.
|
| services.nextcloud.settings | Extra options which should be appended to Nextcloud's config.php file.
|
| services.pgbouncer.settings | Configuration for PgBouncer, see https://www.pgbouncer.org/config.html
for supported values.
|
| services.tor.settings.MainloopStats | See torrc manual.
|
| services.tor.settings.NewCircuitPeriod | See torrc manual.
|
| services.tor.settings.OfflineMasterKey | See torrc manual.
|
| services.hedgedoc.settings.urlPath | URL path for the website
|
| services.suricata.settings.af-xdp | Linux high speed af-xdp capture support, see
docs/capture-hardware/af-xdp.
|
| services.slskd.settings.web.url_base | The base path in the url for web requests.
|
| services.warpgate.settings.mysql.key | Path to MySQL listener private key.
|
| services.keycloak.settings.http-port | On which port Keycloak should listen for new HTTP connections.
|
| services.zitadel.settings.TLS.Key | The TLS certificate private key, as a base64-encoded string
|
| services.anubis.instances.<name>.policy.settings | Additional policy settings merged into the policy file
|
| services.zwave-js.settings.storage.cacheDir | Cache directory
|
| services.sharkey.settings.address | The address that Sharkey binds to.
|
| services.sabnzbd.settings.servers | Usenet provider specification
|
| nix.settings.max-jobs | This option defines the maximum number of jobs that Nix will try to
build in parallel
|
| services.hedgedoc.settings.path | Path to UNIX domain socket to listen on
If specified, host and port will be ignored.
|
| services.hatsu.settings.HATSU_LISTEN_PORT | Port where hatsu should listen for incoming requests.
|
| services.hatsu.settings.HATSU_LISTEN_HOST | Host where hatsu should listen for incoming requests.
|
| services.meilisearch.settings | Configuration settings for Meilisearch
|
| services.firewalld.settings | FirewallD config file
|
| services.moonraker.settings | Configuration for Moonraker
|
| services.mobilizon.settings | Mobilizon Elixir documentation, see
https://docs.joinmobilizon.org/administration/configure/reference/
for supported values.
|
| services.typesense.settings | Typesense configuration
|
| services.canaille.settings.CANAILLE_OIDC | OpenID Connect settings
|
| services.actual.settings.hostname | The address to listen on
|
| services.firezone.server.settings | Environment variables for the Firezone server
|
| services.mosquitto.bridges.<name>.settings | Additional settings for this bridge.
|
| services.evremap.settings.phys | The physical device name to listen on
|
| services.acme-dns.settings.general.nsname | Zone name server.
|
| services.transmission.settings | Settings whose options overwrite fields in
.config/transmission-daemon/settings.json
(each time the service starts)
|
| services.tor.settings.ClientPreferIPv6ORPort | See torrc manual.
|
| services.umurmur.settings.ca_path | Path to your SSL CA certificate.
|
| services.nezha-agent.settings.uuid | Must be set to a unique identifier, preferably a UUID according to
RFC 4122
|
| services.workout-tracker.settings | Extra config options.
|
| services.hickory-dns.settings.zones.*.zone | Zone name, like "example.com", "localhost", or "0.0.127.in-addr.arpa".
|
| services.rspamd-trainer.settings | IMAP authentication configuration for rspamd-trainer
|
| services.zitadel.settings.TLS.Cert | The TLS certificate, as a base64-encoded string
|
| services.suricata.settings.run-as.group | Run Suricata with a specific group-id.
|
| services.maubot.settings.admins | List of administrator users
|
| services.omnom.settings.server.address | Server address.
|
| services.openssh.settings.LogLevel | Gives the verbosity level that is used when logging messages from sshd(8)
|
| services.gancio.settings.log_path | Directory Gancio logs into
|
| services.fediwall.settings.showMedia | Show media in posts
|
| services.navidrome.settings.Port | Port to run Navidrome on.
|
| services.tinyproxy.settings.Port | Specify which port to listen to.
|
| services.pinnwand.settings.footer | The footer in raw HTML.
|
| services.knot-resolver.settings | Nix-based (RFC 42) configuration for Knot Resolver
|
| services.frigate.settings.ffmpeg.path | Package providing the ffmpeg and ffprobe executables below the bin/ directory.
|
| services.apache-kafka.settings."broker.id" | Broker ID. -1 or null to auto-allocate in zookeeper mode.
|
| services.scion.scion-control.settings | scion-control configuration
|
| services.mchprs.settings.address | Address for the server
|
| services.go2rtc.settings.streams | Stream source configuration
|
| services.acme-dns.settings.general.domain | Domain name to serve the requests off of.
|
| services.pretix.settings.pretix.logdir | Directory for storing log files.
|
| services.frigate.settings.cameras | Attribute set of cameras configurations.
https://docs.frigate.video/configuration/cameras
|
| services.xonotic.settings.sv_motd | Text displayed when players join the server.
|
| services.hedgedoc.settings.db | Specify the configuration for sequelize
|
| services.suricata.settings.app-layer | app-layer configuration, see upstream docs.
|
| services.gancio.settings.db.database | Name of the PostgreSQL database
|
| services.karma.settings.listen.address | Hostname or IP to listen on.
|
| services.create_ap.settings | Configuration for create_ap
|
| services.watchdogd.settings | Configuration to put in watchdogd.conf
|
| services.homepage-dashboard.settings | Homepage settings
|
| services.gancio.settings.hostname | The domain name under which the server is reachable.
|
| services.kanboard.phpfpm.settings | Options for kanboard's PHPFPM pool.
|
| services.inadyn.settings.forced-update | Duration (in seconds) after which an update is forced.
|
| services.tor.settings.KeyDirectory | See torrc manual.
|
| services.tor.settings.ClientPreferIPv6DirPort | See torrc manual.
|
| services.tor.settings.ReducedExitPolicy | See torrc manual.
|
| services.part-db.settings.DATABASE_URL | The postgresql database server to connect to
|
| services.influxdb2.settings | configuration options for influxdb2, see https://docs.influxdata.com/influxdb/v2.0/reference/config-options for details.
|
| services.openssh.settings.DenyUsers | If specified, login is denied for all listed users
|
| services.gitlab.pages.settings.listen-http | The address(es) to listen on for HTTP requests.
|
| services.gancio.settings.server.socket | The unix socket for the gancio server to listen on.
|
| services.prowlarr.settings | Attribute set of arbitrary config options
|
| services.whisparr.settings | Attribute set of arbitrary config options
|
| services.sympa.settingsFile | Set of files to be linked in /var/lib/sympa.
|
| services.mediagoblin.paste.settings | Settings which are written into paste.ini.
|
| services.paperless.exporter.settings | Settings to pass to the document exporter as CLI arguments.
|
| hardware.cpu.x86.msr.settings | Parameters for the msr kernel module.
|
| services.tsidp.settings.enableFunnel | Use Tailscale Funnel to make tsidp available on the public internet so it works with SaaS products.
|
| services.postfix-tlspol.settings | The postfix-tlspol configuration file as a Nix attribute set
|
| services.waagent.settings.HttpProxy.Host | If you set http proxy, waagent will use is proxy to access the Internet.
|
| services.waagent.settings.HttpProxy.Port | If you set http proxy, waagent will use this proxy to access the Internet.
|
| services.stalwart-mail.settings | Configuration options for the Stalwart email server
|
| services.openssh.settings.AllowUsers | If specified, login is allowed only for the listed users
|
| services.ente.api.settings.apps.accounts | Set this to the URL where your accounts page is running
|
| services.kubo.settings.Mounts.FuseAllowOther | Allow all users to access the FUSE mount points
|
| services.kanidm.server.settings.origin | The origin of your Kanidm instance
|
| services.firefly-iii.settings.APP_URL | The APP_URL used by firefly-iii internally
|
| services.mx-puppet-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.open-web-calendar.settings | Configuration for the server
|
| services.livekit.ingress.settings | LiveKit Ingress configuration
|
| services.umami.settings.DATABASE_URL | Connection string for the database
|
| services.dsnet.settings.Networks | The CIDR networks that should route through this server
|
| services.peroxide.settings.UserPortImap | The port on which to listen for IMAP connections.
|
| services.peroxide.settings.UserPortSmtp | The port on which to listen for SMTP connections.
|
| services.tor.settings.ControlPortWriteToFile | See torrc manual.
|
| services.tor.settings.ServerDNSResolvConfFile | See torrc manual.
|
| services.tor.settings.DisableNetwork | See torrc manual.
|
| services.gitea.settings.server.SSH_PORT | SSH port displayed in clone URL
|
| services.sympa.domains.<name>.settings | The robot.conf configuration file as key value set
|
| services.matrix-synapse.settings | The primary synapse configuration
|
| services.forgejo.settings.server.ROOT_URL | Full public URL of Forgejo server.
|
| services.nipap.settings.nipapd.db_name | Name of database to use on PostgreSQL server.
|
| services.slskd.settings.shares.filters | Regular expressions of files to exclude from sharing.
|
| services.keycloak.settings.https-port | On which port Keycloak should listen for new HTTPS connections.
|
| services.gemstash.settings.db_url | The database to connect to when using postgres, mysql, or mysql2.
|
| services.bookstack.settings.DB_PORT | The port your database is listening at.
|
| programs.yazi.settings.vfs | Configuration included in vfs.toml
|
| services.traefik.static.settings | Static configuration for Traefik, written in Nix.
This will be serialized to JSON (which is considered valid YAML) at build, and passed to Traefik as --configfile.
|
| services.smartdns.settings | A set that will be generated into configuration file, see the SmartDNS README for details of configuration parameters
|
| services.acme-dns.settings.general.listen | IP+port combination to bind and serve the DNS server on.
|
| services.pretix.settings.celery.broker | URI to the celery broker used for the asynchronous job queue.
|
| services.libeufin.bank.settings | Configuration options for the libeufin bank system config file
|
| services.warpgate.settings.ssh.enable | Whether to enable SSH listener.
|
| services.warpgate.settings.ssh.listen | Listen endpoint of SSH listener.
|
| services.tuned.settings.sections | attribute set of section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.tinc.networks.<name>.settings | Configuration of the Tinc daemon for this network
|
| services.misskey.settings.chmodSocket | The file access mode of the UNIX socket.
|
| services.suricata.settings.af-packet | Linux high speed capture support.
|
| services.zeronsd.servedNetworks.<name>.settings | Settings for zeronsd
|
| services.pds.settings.PDS_REPORT_SERVICE_DID | DID of mod service
|
| services.bluesky-pds.settings.PDS_BSKY_APP_VIEW_DID | DID of bsky frontend
|
| services.go-csp-collector.settings.port | The port to listen on.
|
| services.gitea.settings.mailer.ENABLED | Whether to use an email service to send notifications.
|
| services.headscale.settings | Overrides to config.yaml as a Nix attribute set
|
| services.minidlna.settings.db_dir | Specify the directory to store database and album art cache.
|
| services.grafana.settings.smtp.enabled | Whether to enable SMTP.
|
| services.saunafs.master.settings.DATA_PATH | Data storage directory.
|
| services.bookstack.settings.DB_HOST | The IP or hostname which hosts your database.
|
| services.anuko-time-tracker.settings.helpLink | Help link from the main menu.
|
| services.tor.settings.DownloadExtraInfo | See torrc manual.
|
| services.tor.settings.DataDirectory | See torrc manual.
|
| services.tor.settings.BandwidthRate | See torrc manual.
|
| services.postfix.settings.master.<name>.type | The type of the service
|
| services.rkvm.server.settings.switch-keys | A key list specifying a host switch combination.
A list of key names is available in https://github.com/htrefil/rkvm/blob/master/switch-keys.md.
|
| services.zram-generator.settings | Configuration for zram-generator,
see https://github.com/systemd/zram-generator for documentation.
|
| services.biboumi.settings.ca_file | Specifies which file should be used as the list of trusted CA
when negotiating a TLS session.
|
| services.stash.settings.ui.frontPageContent | Search filters to display on the front page.
|
| services.prowlarr.settings.server.port | Port Number
|
| services.pretix.settings.database.user | Database username.
|
| services.pretix.settings.database.name | Database name.
|
| services.whisparr.settings.server.port | Port Number
|
| services.pds.settings.PDS_REPORT_SERVICE_URL | URL of mod service
|
| services.bluesky-pds.settings.PDS_BSKY_APP_VIEW_URL | URL of bsky frontend
|
| services.lldap.settings.ldap_port | The port on which to have the LDAP server.
|
| services.stash.settings.generated | Path to generated files
|
| services.inadyn.settings.provider.<name>.include | File to include additional settings for this provider from.
|
| services.blackfire-agent.settings | See https://blackfire.io/docs/up-and-running/configuration/agent
|
| services.gitlab.pages.settings.pages-domain | The domain to serve static pages on.
|
| services.moosefs.master.settings.DATA_PATH | Directory for storing master metadata.
|
| services.frigate.settings.mqtt.enabled | Whether to enable MQTT support.
|
| services.imaginary.settings | Command line arguments passed to the imaginary executable, stripped of
the prefix -
|
| services.tlsrpt.collectd.settings | Flags from tlsrpt-collectd(1) as key-value pairs.
|
| services.evremap.settings.remap.*.input | The key sequence that should be remapped
|
| services.chhoto-url.settings.site_url | The URL under which Chhoto URL is externally reachable.
|
| services.fediwall.settings.hideBoosts | Hide boosts
|
| services.bluesky-pds.settings.LOG_ENABLED | Enable logging
|
| boot.initrd.unl0kr.settings | Configuration for unl0kr
|
| nix.settings.cores | This option defines the maximum number of concurrent tasks during
one build
|
| services.suwayomi-server.settings | Configuration to write to server.conf
|
| services.cross-seed.settings.torrentDir | Directory containing torrent files, or if you're using a torrent
client integration and injection - your torrent client's .torrent
file store/cache.
|
| services.slskd.settings.global.upload.slots | Limit of the number of concurrent upload slots.
|
| services.veilid.settings.logging.api.level | The minimum priority of api events to be logged.
|
| services.openssh.settings.StrictModes | Whether sshd should check file modes and ownership of directories
|
| services.nipap.settings.nipapd.db_host | PostgreSQL host to connect to
|
| services.tor.settings.TestingTorNetwork | See torrc manual.
|
| services.tor.settings.LogMessageDomains | See torrc manual.
|
| services.tor.settings.RefuseUnknownExits | See torrc manual.
|
| services.rosenpass.settings.peers | List of peers to exchange keys with.
|
| services.peering-manager.settings | Configuration options to set in configuration.py
|
| services.gitlab.pages.settings.listen-https | The address(es) to listen on for HTTPS requests.
|
| services.amule.settings.WebServer.Enabled | Set to 1 to enable the web server
|
| services.gitlab.pages.settings.listen-proxy | The address(es) to listen on for proxy requests.
|
| services.cryptpad.settings.adminKeys | List of public signing keys of users that can access the admin panel
|
| services.misskey.settings.redisForJobQueue.port | The Redis port.
|
| services.misskey.settings.redisForJobQueue.host | The Redis host.
|
| services.fediwall.settings.loadPublic | Load public posts
|
| services.fediwall.settings.playVideos | Autoplay videos in posts
|
| services.fediwall.settings.loadTrends | Load trending posts
|
| services.peertube-runner.settings | Configuration for peertube-runner
|
| hardware.nfc-nci.settings | Configuration to be written to the libncf-nci configuration files
|
| services.gitea.settings.server.DISABLE_SSH | Disable external SSH feature.
|
| services.pretix.settings.database.host | Database host or socket path.
|
| services.warpgate.settings.http.listen | Listen endpoint of HTTP listener.
|
| services.displayManager.gdm.settings | Options passed to the gdm daemon
|
| services.misskey.settings.redisForJobQueue | ioredis options for the job queue
|
| services.firefly-iii.settings.DB_HOST | The machine which hosts your database
|
| services.opensearch.settings | OpenSearch configuration.
|
| services.wgautomesh.settings | Configuration for wgautomesh.
|
| services.gnome.gnome-settings-daemon.enable | Whether to enable GNOME Settings Daemon.
|
| services.stash.settings.nobrowser | If we should not auto-open a browser window on startup
|
| services.veilid.settings.core.network.upnp | Should the app try to improve its incoming network connectivity using UPnP?
|
| services.forgejo.settings.server.HTTP_PORT | Listen port
|
| services.hedgedoc.settings.domain | Domain to use for website
|
| services.journald.upload.settings | Configuration for journal-upload
|
| services.suricata.settings.rule-files | Files to load suricata-update managed rules, relative to 'default-rule-path'.
|
| services.sourcehut.settings.mail.pgp-key-id | OpenPGP key identifier.
|
| services.forgejo.settings.server.DOMAIN | Domain name of your server.
|
| services.headscale.settings.log.level | headscale log level.
|
| services.tlsrpt.reportd.settings.dbname | Path to the sqlite database.
|
| services.kanidm.server.settings.db_path | Path to Kanidm database.
|
| services.libeufin.nexus.settings | Configuration options for the libeufin nexus config file
|
| services.taler.exchange.settings | Configuration options for the taler exchange config file
|
| services.taler.merchant.settings | Configuration options for the taler merchant config file
|
| services.waagent.settings.OS.EnableRDMA | If enabled, the agent attempts to install and then load an RDMA kernel driver
that matches the version of the firmware on the underlying hardware.
|
| services.sftpgo.settings.ftpd.bindings | Configure listen addresses and ports for ftpd.
|
| services.matrix-synapse.settings.redis | Redis configuration for synapse
|
| programs.yazi.settings.yazi | Configuration included in yazi.toml
|
| services.slskd.settings.web.https.disabled | Disable the built-in HTTPS server
|
| services.ente.api.settings.apps.public-albums | If you're running a self hosted instance and wish to serve public links,
set this to the URL where your albums web app is running.
|
| services.litestream.settings | See the documentation.
|
| services.rebuilderd.settings | Configuration for rebuilderd (rebuilderd.conf)
|
| services.lemmy.settings.captcha.enabled | Enable Captcha.
|
| services.opengfw.settings.ruleset.geoip | Path to geoip.dat.
|
| services.lldap.settings.ldap_host | The host address that the LDAP server will be bound to.
|
| services.lldap.settings.http_host | The host address that the HTTP server will be bound to.
|
| services.lldap.settings.http_port | The port on which to have the HTTP server, for user login and administration.
|
| services.openssh.settings.UseDns | Specifies whether sshd(8) should look up the remote host name, and to check that the resolved host name for
the remote IP address maps back to the very same IP address
|
| services.forgejo.settings.server.HTTP_ADDR | Listen address
|
| services.taler.settings.taler.CURRENCY | The currency which taler services will operate with
|
| services.crowdsec.settings.console | Console Configuration attributes
|
| services.fediwall.settings.servers | Servers to load posts from
|
| services.quickwit.settings.version | Configuration file version.
|
| services.umurmur.settings.channels | Channel tree definitions.
|
| services.hedgedoc.settings.useSSL | Enable to use SSL server.
|
| services.kanidm.server.settings.tls_key | TLS key in pem format.
|
| services.acme-dns.settings.database.engine | Database engine to use.
|
| services.scanservjs.settings | Config to set in config.local.js's afterConfig.
|
| services.reposilite.settings | Configuration written to the reposilite.cdn file
|
| services.canaille.settings.SECRET_KEY | Flask Secret Key
|
| services.misskey.settings.redisForPubsub | ioredis options for pubsub
|
| services.pgbouncer.settings.users | Optional
|
| services.pgbouncer.settings.peers | Optional
|
| services.draupnir.settings.dataPath | The path Draupnir will store its state/data in.
This option is read-only.
If you want to customize where this data is stored, use a bind mount.
|
| services.journald.remote.settings | Configuration in the journal-remote configuration file
|
| services.zammad.database.settings | The database.yml configuration file as key value set
|
| services.anuko-time-tracker.settings.forumLink | Forum link from the main menu.
|
| services.tor.settings.BandwidthBurst | See torrc manual.
|
| services.tsidp.settings.debugAllRequests | For development
|
| services.tor.settings.CacheDirectory | See torrc manual.
|
| services.umurmur.settings.bindport | Port to bind to (UDP and TCP).
|
| services.openbao.settings.listener | Configure a listener for responding to requests.
|
| services.acme-dns.settings.general.nsadmin | Zone admin email address for SOA.
|
| services.scrutiny.settings.web.listen.port | Port for web application to listen on.
|
| services.postfix.settings.master.<name>.name | The name of the service to run
|
| services.misskey.settings.redisForPubsub.port | The Redis port.
|
| services.misskey.settings.redisForPubsub.host | The Redis host.
|
| services.yggdrasil.settings | Configuration for yggdrasil, as a structured Nix attribute set
|
| services.pds.settings.PDS_DATA_DIRECTORY | Directory to store state
|
| services.lasuite-meet.settings.DJANGO_DATA_DIR | Path to the data directory
|
| services.matrix-hookshot.settings | config.yml configuration as a Nix attribute set
|
| services.openssh.settings.DenyGroups | If specified, login is denied for all users part of the listed
groups
|
| services.cryptpad.settings.logToStdout | Controls whether log output should go to stdout of the systemd service
|
| nix.settings.extra-sandbox-paths | Directories from the host filesystem to be included
in the sandbox.
|
| services.epgstation.settings | Options to add to config.yml
|
| services.maubot.settings.database | The full URI to the database
|
| services.rsyncd.settings.sections | attribute set of section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.mautrix-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.easytier.instances.<name>.settings | Settings to generate easytier-‹name›.toml
|
| services.canaille.settings.SERVER_NAME | The domain name on which canaille will be served.
|
| services.freeciv.settings.quitidle | Quit if no players for given time in seconds.
|
| services.freeciv.settings.Database | Enable database connection with given configuration.
|
| services.umurmur.settings.password | Required password to join server, if specified.
|
| services.postsrsd.settings.domains | List of local domains, that do not require rewriting.
|
| services.anuko-time-tracker.settings.email.mode | Mail sending mode
|
| services.pretix.settings.pretix.datadir | Directory for storing user uploads and similar data.
|
| services.hatsu.settings.HATSU_DATABASE_URL | Database URL.
|
| services.public-inbox.settings.coderepo | code repositories
|
| services.scrutiny.settings.web.listen.host | Interface address for web application to bind to.
|
| services.biboumi.settings.db_name | The name of the database to use
|
| services.samba.settings.global.security | Samba security type.
|
| services.broadcast-box.settings | Attribute set of environment variables.
https://github.com/Glimesh/broadcast-box#environment-variables
The status API exposes stream keys so DISABLE_STATUS is enabled
by default.
|
| security.pam.u2f.settings.debug | Debug output to stderr.
|
| services.tor.settings.ShutdownWaitLength | See torrc manual.
|
| services.tuned.settings.globalSection | global section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.openssh.settings.AllowGroups | If specified, login is allowed only for users part of the
listed groups
|
| services.matrix-conduit.settings | Generates the conduit.toml configuration file
|
| services.pretalx.settings.redis.session | Whether to use redis as the session storage.
|
| services.sourcehut.settings.mail.smtp-from | Outgoing SMTP FROM.
|
| services.dnsmasq.settings | Configuration of dnsmasq
|
| services.traccar.settings | config.xml configuration as a Nix attribute set
|
| services.metricbeat.settings | Configuration for metricbeat
|
| services.routinator.settings | Configuration for Routinator 3000, see https://routinator.docs.nlnetlabs.nl/en/stable/manual-page.html#configuration-file for options.
|
| services.freeciv.settings.Announce | Announce game in LAN using given protocol.
|
| services.sabnzbd.settings.servers.<name>.ssl | Whether the server supports TLS
|
| services.umurmur.settings.bindaddr | IPv4 address to bind to
|
| services.pretalx.settings.celery.broker | URI to the celery broker used for the asynchronous job queue.
|
| services.pretix.settings.celery.backend | URI to the celery backend used for the asynchronous job queue.
|
| services.neard.settings.General.ResetOnError | Power cycle the adapter when getting a driver error from the kernel.
|
| services.openssh.settings.AcceptEnv | Specifies what environment variables sent by the client will be copied into the session's
environment
|
| services.meshcentral.settings | Settings for MeshCentral
|
| services.gancio.settings.log_level | Gancio log level.
|
| services.hedgedoc.settings.allowOrigin | List of domains to whitelist.
|
| services.tinyproxy.settings.Listen | Specify which address to listen to.
|
| services.mosquitto.listeners.*.settings | Additional settings for this listener.
|
| services.gitlab.pages.settings.gitlab-server | Public GitLab server URL.
|
| services.legit.settings.dirs.templates | Directories where template files are located.
|
| services.gitea.settings.mailer.PROTOCOL | Which mail server protocol to use.
|
| services.headscale.settings.oidc.scope | Scopes used in the OIDC flow.
|
| services.misskey.settings.db.disableCache | Whether to disable caching queries.
|
| services.warpgate.settings.mysql.enable | Whether to enable MySQL listener.
|
| services.warpgate.settings.mysql.listen | Listen endpoint of MySQL listener.
|
| services.firefly-iii.settings.APP_KEY_FILE | The path to your appkey
|
| services.inadyn.settings.custom.<name>.ddns-path | DDNS server path
|
| services.gitea.settings.server.STATIC_ROOT_PATH | Upper level of template and static files path.
|
| services.livekit.settings.redis.address | Host and port used to connect to a redis instance.
|
| services.opengfw.settings.workers.count | Number of workers
|
| services.kea.dhcp6.configFile | Kea DHCP6 configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp6-srv.html
|
| services.kea.dhcp4.configFile | Kea DHCP4 configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/dhcp4-srv.html
|
| services.scanservjs.settings.host | The IP to listen on.
|
| services.scanservjs.settings.port | The port to listen on.
|
| services.sourcehut.settings.mail.smtp-port | Outgoing SMTP port.
|
| services.sourcehut.settings.mail.smtp-host | Outgoing SMTP host.
|
| services.sourcehut.settings.mail.smtp-user | Outgoing SMTP user.
|
| services.nvme-rs.settings.email.smtp_port | SMTP server port
|
| services.mchprs.settings.schemati | Mimic the verification and directory layout used by the
Open Redstone Engineers
Schemati plugin
|
| services.lubelogger.settings | Additional configuration for LubeLogger, see https://docs.lubelogger.com/Environment%20Variables for supported values.
|
| services.photoprism.settings | See the getting-started guide for available options.
|
| services.freeciv.settings.Newusers | Whether to enable new users to login if auth is enabled.
|
| services.aesmd.settings.whitelistUrl | URL to retrieve authorized Intel SGX enclave signers.
|
| services.suricata.settings.plugins | Plugins -- Experimental -- specify the filename for each plugin shared object.
|
| services.openssh.settings.PermitRootLogin | Whether the root user can login using ssh.
|
| services.suricata.settings.stats | Engine statistics such as packet counters, memory use counters and others can be logged in several ways
|
| services.wastebin.settings.RUST_LOG | Influences logging
|
| security.please.settings | Please configuration
|
| services.sabnzbd.settings.servers.<name>.host | Hostname of the server
|
| services.sabnzbd.settings.servers.<name>.port | Port of the server
|
| services.tor.settings.FascistFirewall | See torrc manual.
|
| services.sabnzbd.settings.servers.<name>.name | The name of the server
|
| services.postgrest.settings.db-uri | libpq connection parameters as documented in:
https://www.postgresql.org/docs/current/libpq-connect.html#LIBPQ-PARAMKEYWORDS
The settings.db-uri.password and settings.db-uri.passfile options are blocked
|
| services.opengfw.settings.ruleset | The path to load specific local geoip/geosite db files
|
| hardware.amdgpu.amdvlk.settings | Runtime settings for AMDVLK to be configured /etc/amd/amdVulkanSettings.cfg
|
| services.kubo.settings.Addresses.Swarm | Where Kubo listens for incoming p2p connections
|
| services.sftpgo.settings.httpd.bindings | Configure listen addresses and ports for httpd.
|
| services.pretix.settings.redis.sessions | Whether to use redis as the session storage.
|
| services.sftpgo.settings.sftpd.bindings | Configure listen addresses and ports for sftpd.
|
| services.suricata.settings.stats.enable | Whether to enable suricata global stats.
|
| security.krb5.settings | Structured contents of the krb5.conf file
|
| services.rkvm.client.settings.password | Shared secret token to authenticate the client
|
| services.rkvm.server.settings.password | Shared secret token to authenticate the client
|
| services.anuko-time-tracker.settings.email.smtpHost | MTA hostname.
|
| services.grafana.settings.database.type | Database type.
|
| services.anuko-time-tracker.settings.email.smtpPort | MTA port.
|
| services.pretalx.settings.database.name | Database name.
|
| services.pretalx.settings.database.user | Database username.
|
| services.go-autoconfig.settings | Configuration for go-autoconfig
|
| services.sourcehut.settings."sr.ht".site-info | The top-level info page for your site.
|
| services.sourcehut.settings."sr.ht".site-name | The name of your network of sr.ht-based sites.
|
| services.grafana.settings.paths.plugins | Directory where grafana will automatically scan and look for plugins
|
| services.gateone.settingsDir | Path of configuration files for GateOne.
|
| services.cryptpad.settings.httpSafeOrigin | Cryptpad sandbox URL
|
| services.reposilite.settings.port | The TCP port to bind to.
|
| services.postgresql.settings.port | The port on which PostgreSQL listens.
|
| services.sourcehut.settings.mail.error-to | Address receiving application exceptions
|
| services.suricata.settings.vars.port-groups | The port group variables for suricata.
|
| services.librechat.settings | A free-form attribute set that will be written to librechat.yaml
|
| services.acme-dns.settings.general.records | Predefined DNS records served in addition to the _acme-challenge TXT records.
|
| services.minidlna.settings.inotify | Whether to enable inotify monitoring to automatically discover new files.
|
| services.filesender.settings | Configuration options used by FileSender
|
| services.homebridge.settings | Configuration options for homebridge
|
| services.snapserver.settings | Snapserver configuration
|
| services.privatebin.settings | Options for privatebin configuration
|
| services.mattermost.settings | Additional configuration options as Nix attribute set in config.json schema.
|
| nix.settings | Configuration for Nix, see
https://nixos.org/manual/nix/stable/command-ref/conf-file.html or
nix.conf(5) for available options
|
| services.rosenpass.settings.listen | List of local endpoints to listen for connections.
|
| services.umami.settings.DISABLE_UPDATES | Disables the check for new versions of Umami.
|
| services.suricata.settings.vars.address-groups | The address group variables for suricata, if not defined the
default value of suricata (see example) will be used
|
| services.gitea.settings.server.PROTOCOL | Listen protocol. +unix means "over unix", not "in addition to."
|
| services.fediwall.settings.hideReplies | Hide replies
|
| services.anuko-time-tracker.settings.email.smtpAuth | MTA requires authentication.
|
| services.anuko-time-tracker.settings.email.smtpUser | MTA authentication username.
|
| services.grafana.settings.database.name | The name of the Grafana database.
|
| services.headscale.settings.log.format | headscale log format.
|
| programs.gamemode.settings | System-wide configuration for GameMode (/etc/gamemode.ini)
|
| services.inadyn.settings.provider.<name>.ssl | Whether to use HTTPS for this DDNS provider.
|
| services.routinator.settings.log | A string specifying where to send log messages to
|
| services.shairport-sync.settings | Configuration options for Shairport-Sync
|
| services.epgstation.settings.port | HTTP port for EPGStation to listen on.
|
| services.tor.settings.VirtualAddrNetworkIPv4 | See torrc manual.
|
| services.tor.settings.VirtualAddrNetworkIPv6 | See torrc manual.
|
| services.snips-sh.settings.SNIPS_SSH_INTERNAL | The internal SSH address of the service
|
| services.tor.settings.AccountingMax | See torrc manual.
|
| programs.direnv.settings | Direnv configuration
|
| services.headscale.settings.dns.split | Split DNS configuration (map of domains and which DNS server to use for each)
|
| services.c2fmzq-server.settings.verbose | The level of logging verbosity: 1:Error 2:Info 3:Debug
|
| services.languagetool.settings | Configuration file options for LanguageTool, see
'languagetool-http-server --help'
for supported settings.
|
| services.opensnitch.settings | opensnitchd configuration
|
| services.nebula.networks.<name>.settings | Nebula configuration
|
| services.x2goserver.settings | x2goserver.conf ini configuration as nix attributes
|
| services.netbox.settings.ALLOWED_HOSTS | A list of valid fully-qualified domain names (FQDNs) and/or IP
addresses that can be used to reach the NetBox service.
|
| services.postfix.settings.master.<name>.args | Arguments to pass to the command
|
| services.resolved.settings.Resolve.DNS | List of IP addresses to query as recursive DNS resolvers.
|
| services.headscale.settings.derp.urls | List of urls containing DERP maps
|
| services.sourcehut.settings."sr.ht".site-blurb | Blurb for your site.
|
| services.sourcehut.settings."sr.ht".owner-name | Owner's name.
|
| services.lasuite-meet.settings.LIVEKIT_API_URL | URL to the livekit server
|
| services.grafana.settings.database.user | The database user (not applicable for sqlite3).
|
| services.grafana.settings.smtp.key_file | File path to a key file.
|
| services.sabnzbd.settings.misc.email_to | Receiving address for email alerts
|
| services.pretalx.settings.database.host | Database host or socket path.
|
| services.parsedmarc.settings.smtp.to | The addresses to send outgoing mail to.
|
| services.frigate.settings.database.path | Path to the SQLite database used
|
| programs.yazi.settings.theme | Configuration included in theme.toml
|
| services.evremap.settings.remap.*.output | The key sequence that should be output when the input sequence is entered
|
| services.grafana-to-ntfy.settings.ntfyBAuthPass | The path to the password for the specified ntfy-sh user
|
| services.dsnet.settings.ExternalIP | The external IP address of the server
|
| services.amule.settings.eMule.IncomingDir | Directory where aMule moves completed downloads
|
| services.lokinet.settings.network.exit | Whether to act as an exit node
|
| services.wg-access-server.settings.storage | A storage backend connection string
|
| services.yggdrasil.settings.Peers | List of outbound peer connection strings
|
| services.hickory-dns.settings.zones.*.file | Path to the .zone file
|
| services.inadyn.settings.custom.<name>.ddns-server | DDNS server name.
|
| services.sympa.settingsFile.<name>.text | Text of the file.
|
| services.bluesky-pds.settings.PDS_CRAWLERS | URL of crawlers
|
| services.zipline.settings.CORE_HOSTNAME | The hostname to listen on.
|
| services.frp.instances.<name>.settings | Frp configuration, for configuration options
see the example of client
or server on github.
|
| programs.foot.settings | Configuration for foot terminal emulator
|
| programs.htop.settings | Extra global default configuration for htop
which is read on first startup only
|
| services.opengfw.settings.workers.queueSize | Worker queue size.
|
| services.vault-agent.instances.<name>.settings | Free-form settings written directly to the config.json file
|
| services.xonotic.settings.hostname | The name that will appear in the server list. $g_xonoticversion
gets replaced with the current version.
|
| services.postsrsd.settings.chroot-dir | Path to chroot into at runtime as an additional layer of protection.
We confine the runtime environment through systemd hardening instead, so this option is read-only.
|
| services.autotierfs.settings | The contents of the configuration file for autotier
|
| services.grafana.settings.database.wal | For sqlite3 only
|
| services.cryptpad.settings.maxWorkers | Number of child processes, defaults to number of cores available
|
| services.prometheus.exporters.nginxlog.settings | All settings of nginxlog expressed as an Nix attrset
|
| services.hedgedoc.settings.uploadsPath | Directory for storing uploaded images.
|
| services.cryptpad.settings.httpAddress | Address on which the Node.js server should listen
|
| services.tor.settings.AssumeReachable | See torrc manual.
|
| services.tor.settings.ServerDNSSearchDomains | See torrc manual.
|
| services.tor.settings.WarnPlaintextPorts | See torrc manual.
|
| services.nvme-rs.settings.thresholds | Threshold configuration for NVMe monitoring
|
| services.tor.settings.RelayBandwidthRate | See torrc manual.
|
| services.tor.settings.UnixSocksGroupWritable | See torrc manual.
|
| services.tor.settings.AutomapHostsOnResolve | See torrc manual.
|
| services.tor.settings.DormantOnFirstStartup | See torrc manual.
|
| services.maubot.settings.server.hostname | The IP to listen on
|
| services.metricbeat.settings.tags | Tags to place on the shipped metrics
|
| services.metricbeat.settings.name | Name of the beat
|
| services.yggdrasil-jumper.settings | Configuration for Yggdrasil Jumper as a Nix attribute set.
|
| services.grafana.settings.server.socket | Path where the socket should be created when protocol=socket
|
| services.opencloud.settings | Additional YAML configuration for OpenCloud services
|
| services.aesmd.settings.defaultQuotingType | Attestation quote type.
|
| services.sourcehut.settings."hg.sr.ht".origin | URL hg.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."hg.sr.ht".hg_ssh | Path to hg-ssh (if not in $PATH).
|
| services.sourcehut.settings."hg.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."hg.sr.ht".debug-port | Port to bind the debug server to.
|
| services.snapserver.settings.tcp.port | Port to listen on for snapclient connections.
|
| services.tlsrpt.fetcher.settings.storage | Path to the collectd sqlite database.
|
| services.biboumi.settings.hostname | The hostname served by the XMPP gateway
|
| services.pretix.settings.redis.location | URI to the redis server, used to speed up locking, caching and session storage.
|
| services.warpgate.settings.log.send_to | Path of UNIX socket of log forwarder
|
| services.centrifugo.settings | Declarative Centrifugo configuration
|
| services.bookstack.settings.APP_URL | The root URL that you want to host BookStack on
|
| services.grafana-to-ntfy.settings.ntfyBAuthUser | The ntfy-sh user to use for authenticating with the ntfy-sh instance
|
| services.waagent.settings.Logs.Verbose | If you set this option, log verbosity is boosted
|
| services.c2fmzq-server.settings.database | Path of the database
|
| services.stash.settings.blobs_path | Path to blobs
|
| services.headscale.settings.oidc.issuer | URL to OpenID issuer.
|
| services.actual.settings.serverFiles | The server will put an account.sqlite file in this directory, which will contain the (hashed) server password, a list of all the budget files the server knows about, and the active session token (along with anything else the server may want to store in the future).
|
| services.crowdsec-firewall-bouncer.settings | Settings for the main CrowdSec Firewall Bouncer
|
| services.mympd.settings.http_port | The HTTP port where mympd's web interface will be available
|
| services.reaction.settingsFiles | Configuration for reaction, see the wiki.
reaction supports JSON, YAML and JSONnet
|
| services.postgrest.settings | PostgREST configuration as documented in:
https://docs.postgrest.org/en/stable/references/configuration.html#list-of-parameters
db-uri is represented as an attribute set, see settings.db-uri
The settings.jwt-secret option is blocked
|
| services.samba.settings.global."invalid users" | List of users who are denied to login via Samba.
|
| services.invidious-router.settings | Configuration for invidious-router
|
| services.parsedmarc.settings.smtp.ssl | Use an encrypted SSL/TLS connection.
|
| services.parsedmarc.settings.imap.ssl | Use an encrypted SSL/TLS connection.
|
| services.forgejo.settings.server.SSH_PORT | SSH port displayed in clone URL
|
| services.tor.settings.CellStatistics | See torrc manual.
|
| services.snips-sh.settings.SNIPS_HTTP_INTERNAL | The internal HTTP address of the service
|
| services.tor.settings.OptimisticData | See torrc manual.
|
| services.tor.settings.DirReqStatistics | See torrc manual.
|
| services.rsyncd.settings.globalSection | global section of an INI file (attrs of INI atom (null, bool, int, float or string))
|
| services.rosenpass.settings.peers.*.peer | WireGuard public key corresponding to the remote Rosenpass peer.
|
| services.umami.settings.TRACKER_SCRIPT_NAME | Allows you to assign a custom name to the tracker script different from the default script.js.
|
| services.sitespeed-io.runs.*.settings | Configuration for sitespeed-io, see
https://www.sitespeed.io/documentation/sitespeed.io/configuration/
for available options
|
| security.auditd.settings | auditd configuration file contents
|
| services.sourcehut.settings.mail.error-from | Address sending application exceptions
|
| services.sourcehut.settings."hub.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."man.sr.ht".origin | URL man.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."hub.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."git.sr.ht".origin | URL git.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."hub.sr.ht".origin | URL hub.sr.ht is being served at (protocol://domain)
|
| services.acme-dns.settings.general.protocol | Protocols to serve DNS responses on.
|
| services.pretix.settings.pretix.cachedir | Directory for storing temporary files.
|
| services.wgautomesh.settings.peers | wgautomesh peer list.
|
| services.kavita.settings.IpAddresses | IP Addresses to bind to
|
| services.bluesky-pds.settings.PDS_HOSTNAME | Instance hostname (base domain name)
|
| services.privoxy.settings.listen-address | Pair of address:port the proxy server is listening to.
|
| services.lokinet.settings.dns.upstream | Upstream resolver(s) to use as fallback for non-loki addresses
|
| services.anuko-time-tracker.settings.email.smtpDebug | Debug mail sending.
|
| services.anuko-time-tracker.settings.email.sender | Default sender for mail.
|
| services.parsedmarc.settings.imap.port | The IMAP server port.
|
| services.parsedmarc.settings.smtp.user | The SMTP server username.
|
| services.parsedmarc.settings.smtp.port | The SMTP server port.
|
| services.omnom.settings.db.connection | Database connection URI.
|
| services.parsedmarc.settings.imap.user | The IMAP server username.
|
| services.parsedmarc.settings | Configuration parameters to set in
parsedmarc.ini
|
| services.grafana.settings.database.path | Only applicable to sqlite3 database
|
| <imports = [ pkgs.php.services.default ]>.php-fpm.settings | PHP FPM configuration
|
| services.sourcehut.settings."hg.sr.ht".repos | Path to mercurial repositories on disk
|
| services.bitmagnet.settings.dht_server | DHT server settings
|
| services.garage.settings.data_dir | The directory in which Garage will store the data blocks of objects
|
| services.tor.settings.ServerDNSAllowBrokenConfig | See torrc manual.
|
| services.tor.settings.ExitPolicyRejectPrivate | See torrc manual.
|
| services.librespeed.frontend.settings | Override default settings of the speedtest web client
|
| services.pretalx.settings.celery.backend | URI to the celery backend used for the asynchronous job queue.
|
| services.dsnet.settings.ExternalIP6 | The external IPv6 address of the server
|
| services.btrbk.instances.<name>.settings | configuration options for btrbk
|
| services.gitea.settings.mailer.SENDMAIL_PATH | Path to sendmail binary or script.
|
| services.grafana.settings.smtp.startTLS_policy | StartTLS policy when connecting to server.
|
| services.suwayomi-server.settings.server.ip | The ip that Suwayomi will bind to.
|
| services.snapserver.settings.http.port | Port to listen on for snapclient connections.
|
| services.parsedmarc.settings.smtp.from | The From address to use for the
outgoing mail.
|
| services.suricata.settings.host-mode | If the Suricata box is a router for the sniffed networks, set it to 'router'
|
| services.sourcehut.settings."sr.ht".owner-email | Owner's email.
|
| services.navidrome.settings.Address | Address to run Navidrome on.
|
| services.pid-fan-controller.settings.fans | List of fans to be controlled.
|
| services.watchdogd.settings.timeout | The WDT timeout before reset.
|
| services.watchdogd.settings.safe-exit | With safeExit enabled, the daemon will ask the driver to disable the WDT before exiting
|
| services.veilid.settings.logging.api.enabled | Events of type 'api' will be logged.
|
| services.veilid.settings.logging.system.level | The minimum priority of system events to be logged.
|
| services.openssh.settings.GatewayPorts | Specifies whether remote hosts are allowed to connect to
ports forwarded for the client
|
| services.sourcehut.settings."sr.ht".source-url | The source code for your fork of sr.ht.
|
| services.imaginary.settings.return-size | Return the image size in the HTTP headers.
|
| services.postgrest.settings.server-port | The TCP port to bind the web server.
|
| services.sourcehut.settings.mail.pgp-pubkey | OpenPGP public key.
|
| services.sourcehut.settings."git.sr.ht".repos | Path to git repositories on disk
|
| services.headscale.settings.derp.paths | List of file paths containing DERP maps
|
| services.mautrix-discord.settings.bridge | Bridge configuration
|
| services.collabora-online.settings | Configuration for Collabora Online WebSocket Daemon, see
https://sdk.collaboraonline.com/docs/installation/Configuration.html, or
https://github.com/CollaboraOnline/online/blob/master/coolwsd.xml.in for the default
configuration.
|
| services.wordpress.sites.<name>.settings | Structural Wordpress configuration
|
| services.sourcehut.settings."lists.sr.ht".redis | The Redis connection used for the Celery worker.
|
| services.etebase-server.settings.global.debug | Whether to set django's DEBUG flag.
|
| services.parsedmarc.settings.imap.host | The IMAP server hostname or IP address.
|
| services.parsedmarc.settings.smtp.host | The SMTP server hostname or IP address.
|
| services.angrr.settings.profile-policies | Profile GC root policies.
|
| services.moosefs.cgiserver.settings | GUI server configuration options.
|
| services.tor.settings.RelayBandwidthBurst | See torrc manual.
|
| services.opensearch.settings."http.port" | The port to listen on for HTTP traffic.
|
| services.vmalert.settings."notifier.url" | Prometheus Alertmanager URL
|
| services.yggdrasil.settings.Listen | Listen addresses for incoming connections
|
| services.postfix-tlspol.settings.server.log-level | Log level
|
| services.dependency-track.settings | See https://docs.dependencytrack.org/getting-started/configuration/#default-configuration for possible options
|
| services.libeufin.nexus.settings.nexus-ebics.BIC | BIC of the bank account that is associated with the EBICS subscriber.
|
| services.filebeat.settings | Configuration for filebeat
|
| services.sftpgo.settings.smtp.auth_type |
0: Plain
1: Login
2: CRAM-MD5
|
| services.openldap.settings.children | Child entries of the current entry, with recursively the same structure.
|
| services.openldap.settings.includes | LDIF files to include after the parent's attributes but before its children.
|
| services.gitlab.pages.settings | Configuration options to set in the GitLab Pages config
file
|
| services.sourcehut.settings."todo.sr.ht".origin | URL todo.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."meta.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."todo.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."meta.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."todo.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."meta.sr.ht".origin | URL meta.sr.ht is being served at (protocol://domain)
|
| services.forgejo.settings.server.DISABLE_SSH | Disable external SSH feature.
|
| services.postgrest.settings.db-config | Enables the in-database configuration.
https://docs.postgrest.org/en/stable/references/configuration.html#in-database-configuration
This is enabled by default upstream, but disabled by default in this module.
|
| services.matrix-hookshot.settings.passFile | A passkey used to encrypt tokens stored inside the bridge
|
| services.grocy.settings.calendar.firstDayOfWeek | Which day of the week (0=Sunday, 1=Monday etc.) should be the
first day.
|
| services.lokinet.settings.network.exit-node | Specify a .loki address and an optional ip range to use as an exit broker
|
| services.hercules-ci-agent.settings.apiBaseUrl | API base URL that the agent will connect to
|
| services.bluesky-pds.settings.PDS_BLOB_UPLOAD_LIMIT | Size limit of uploaded blobs in bytes
|
| services.umurmur.settings.max_users | Maximum number of concurrent clients allowed.
|
| services.amule.settings.WebServer.Password | MD5 hash of the password, obtainaible with echo "<password>" | md5sum | cut -d ' ' -f 1
|
| services.umami.settings.APP_SECRET_FILE | A file containing a secure random string
|
| security.krb5.settings.module | Modules to obtain Kerberos configuration from.
|
| services.pretix.settings.pretix.currency | Default currency for events in its ISO 4217 three-letter code.
|
| services.libeufin.nexus.settings.nexus-httpd.PORT | The port on which libeufin-bank should listen.
|
| services.sftpgo.settings.ftpd.bindings.*.port | The port for serving FTP requests
|
| security.pam.u2f.settings | Options to pass to the PAM module
|
| services.scrutiny.collector.settings | Collector settings to be rendered into the collector configuration file
|
| services.typesense.settings.server.api-port | Port on which the Typesense API service listens.
|
| services.warpgate.settings.postgres.key | Path to PostgreSQL listener private key.
|
| services.tor.settings.UseDefaultFallbackDirs | See torrc manual.
|
| services.tor.settings.AccountingStart | See torrc manual.
|
| services.tor.settings.ProtocolWarnings | See torrc manual.
|
| services.tor.settings.EntryStatistics | See torrc manual.
|
| services.lasuite-docs.settings.CELERY_BROKER_URL | URL of the redis backend for celery
|
| services.lasuite-meet.settings.CELERY_BROKER_URL | URL of the redis backend for celery
|
| services.opengfw.settings.ruleset.geosite | Path to geosite.dat.
|
| services.bonsaid.settings.*.command | Command to run when this transition is taken
|
| services.mautrix-signal.settings | config.yaml configuration as a Nix attribute set
|
| services.oncall.settings.db.conn.kwargs.database | Database name.
|
| services.umurmur.settings.bindaddr6 | IPv6 address to bind to
|
| services.syncthing.settings.options | The options element contains all other global configuration options
|
| services.xonotic.settings.sv_public | Controls whether the server will be publicly listed.
|
| services.grafana.settings.server.domain | The public facing domain name used to access grafana from a browser
|
| services.traefik.dynamic.settings | Dynamic configuration for Traefik, written in Nix
|
| services.headscale.settings.policy.mode | The mode can be "file" or "database" that defines
where the ACL policies are stored and read from.
|
| services.headscale.settings.policy.path | If the mode is set to "file", the path to a
HuJSON file containing ACL policies.
|
| services.hbase-standalone.settings | configurations in hbase-site.xml, see https://github.com/apache/hbase/blob/master/hbase-server/src/test/resources/hbase-site.xml for details.
|
| services.libeufin.nexus.settings.nexus-ebics.NAME | Legal entity that is associated with the EBICS subscriber.
|
| services.slskd.settings.global.download.slots | Limit of the number of concurrent download slots.
|
| services.typesense.settings.server.data-dir | Path to the directory where data will be stored on disk.
|
| services.public-inbox.settings.coderepo.<name>.dir | Path to a git repository
|
| services.openbao.settings.listener.<name>.type | The listener type to enable.
|
| services.firewalld.settings.RFC3964_IPv4 | Whether to filter IPv6 traffic with 6to4 destination addresses that correspond to IPv4 addresses that should not be routed over the public internet.
|
| services.grafana-image-renderer.settings | Configuration attributes for grafana-image-renderer.
|
| services.scrutiny.settings.web.influxdb.org | InfluxDB organisation under which to store data.
|
| services.reposilite.settings.sslPort | SSL port to bind to
|
| services.kanidm.server.settings.domain | The domain that Kanidm manages
|
| services.grafana.settings.server.protocol | Which protocol to listen.
|
| services.tor.settings.ExitPortStatistics | See torrc manual.
|
| services.tor.settings.AutomapHostsSuffixes | See torrc manual.
|
| services.crab-hole.settings.blocklist.lists | List of blocklists
|
| services.bookstack.settings | Options for Bookstack configuration
|
| services.libeufin.nexus.settings.nexus-ebics.IBAN | IBAN of the bank account that is associated with the EBICS subscriber.
|
| programs.yazi.settings.keymap | Configuration included in keymap.toml
|
| services.canaille.settings.CANAILLE.ACL | Access Control Lists
|
| services.libeufin.nexus.settings.nexus-ebics.HOST_ID | Name of the EBICS host.
|
| programs.lazygit.settings | Lazygit configuration
|
| services.listmonk.database.settings.smtp | List of outgoing SMTP servers
|
| services.suwayomi-server.settings.server.port | The port that Suwayomi will listen to.
|
| services.pretalx.settings.redis.location | URI to the redis server, used to speed up locking, caching and session storage.
|
| services.radicle.ci.broker.settings.triggers | CI triggers.
|
| services.postfix-tlspol.settings.server.cache-file | Path to the cache file.
|
| services.tlsrpt.collectd.settings.storage | Storage backend definition.
|
| services.sabnzbd.settings.servers.<name>.enable | Enable this server by default
|
| services.angrr.settings.touch.project-globs | List of glob patterns to include or exclude files when touching GC roots
|
| services.knot-resolver.settings.workers | The number of running kresd (Knot Resolver daemon) workers
|
| services.postfix.settings.master.<name>.wakeup | Automatically wake up the service after the specified number of
seconds
|
| services.logrotate.settings.<name>.enable | Whether to enable setting individual kill switch.
|
| services.grocy.settings.calendar.showWeekNumber | Show the number of the weeks in the calendar views.
|
| services.suricata.settings.default-rule-path | Path in which suricata-update managed rules are stored by default.
|
| services.sourcehut.settings."hg.sr.ht".api-origin | Origin URL for the API
|
| services.epgstation.settings.encode | Encoding presets for recorded videos.
|
| services.tor.settings.ServerDNSRandomizeCase | See torrc manual.
|
| services.tor.settings.BridgeRecordUsageByCountry | See torrc manual.
|
| services.scrutiny.settings.web.influxdb.port | The port of the InfluxDB instance.
|
| services.samba.settings.global."passwd program" | Path to a program that can be used to set UNIX user passwords.
|
| services.sourcehut.settings."paste.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."pages.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."pages.sr.ht".origin | URL pages.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."lists.sr.ht".debug-port | Port to bind the debug server to.
|
| services.sourcehut.settings."paste.sr.ht".origin | URL paste.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."paste.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."lists.sr.ht".origin | URL lists.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."pages.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."lists.sr.ht".debug-host | Address to bind the debug server to.
|
| services.moosefs.cgiserver.settings.PORT | Port for CGI server to listen on.
|
| services.crowdsec.settings.console.tokenFile | The Console Token file to use.
|
| services.grafana.settings.smtp.cert_file | File path to a cert file.
|
| services.kubo.settings.Addresses.Gateway | Where the IPFS Gateway can be reached
|
| programs.regreet.settings | ReGreet configuration file
|
| services.apache-kafka.settings.listeners | Kafka Listener List
|
| services.postsrsd.settings.srs-domain | Dedicated mail domain used for ephemeral SRS envelope addresses
|
| systemd.settings.Manager | Options for the global systemd service manager
|
| services.peroxide.settings.ServerAddress | The address on which to listen for connections.
|
| services.corteza.settings.HTTP_WEBAPP_ENABLED | Whether to enable webapps.
|
| services.firewalld.settings.DefaultZone | Default zone for connections.
|
| services.matrix-synapse.settings.pid_file | The file to store the PID in.
|
| services.autosuspend.settings | Configuration for autosuspend, see
https://autosuspend.readthedocs.io/en/latest/configuration_file.html#general-configuration
for supported values.
|
| services.immichframe.settings | Configuration for ImmichFrame
|
| services.mollysocket.settings | Configuration for MollySocket
|
| services.forgejo.settings.server.STATIC_ROOT_PATH | Upper level of template and static files path.
|
| services.sourcehut.settings."meta.sr.ht::settings".registration | Whether to enable public registration.
|
| services.hatsu.settings.HATSU_PRIMARY_ACCOUNT | The primary account of your instance (eg 'example.com').
|
| services.inadyn.settings.custom.<name>.hostname | Hostname alias(es).
|
| services.inadyn.settings.custom.<name>.username | Username for this DDNS provider.
|
| services.filebrowser.settings.port | The port to listen on.
|
| services.scrutiny.settings.web.influxdb.host | IP or hostname of the InfluxDB instance.
|
| services.sftpgo.settings.sftpd.bindings.*.port | The port for serving SFTP requests
|
| services.sourcehut.settings."builds.sr.ht".redis | The Redis connection used for the Celery worker.
|
| services.resolved.settings.Resolve.DNSSEC | Whether to validate DNSSEC for DNS lookups.
|
| services.sftpgo.settings.webdavd.bindings | Configure listen addresses and ports for webdavd.
|
| services.postfix.settings.master.<name>.chroot | Whether the service is chrooted to have only access to the
services.postfix.queueDir and the closure of
store paths specified by the program option.
|
| services.sourcehut.settings."git.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."hub.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."man.sr.ht".api-origin | Origin URL for the API
|
| services.tor.settings.MaxCircuitDirtiness | See torrc manual.
|
| services.tor.settings.RejectPlaintextPorts | See torrc manual.
|
| services.suricata.settings.includes | Files to include in the suricata configuration
|
| services.healthchecks.settings | Environment variables which are read by healthchecks (local)_settings.py
|
| services.sourcehut.settings."pages.sr.ht".max-site-size | Maximum size of any given site (post-gunzip), in MiB.
|
| services.sourcehut.settings."hg.sr.ht".srhtext | Path to the srht mercurial extension
(defaults to where the hgsrht code is)
|
| services.writefreely.settings | Writefreely configuration (config.ini)
|
| services.journald.remote.settings.Remote.Seal | Periodically sign the data in the journal using Forward Secure
Sealing.
|
| services.umami.settings.DATABASE_URL_FILE | A file containing a connection string for the database
|
| services.matrix-synapse.settings.redis.enabled | Whether to use redis support
|
| services.anubis.defaultOptions.settings | Freeform configuration via environment variables for Anubis
|
| services.tinyproxy.settings.Filter | Tinyproxy supports filtering of web sites based on URLs or domains
|
| services.cryptpad.settings.httpUnsafeOrigin | This is the URL that users will enter to load your instance
|
| services.sftpgo.settings.httpd.bindings.*.port | The port for serving HTTP(S) requests
|
| services.prometheus.exporters.fritz.settings | Configuration settings for fritz-exporter.
|
| services.gotosocial.settings | Contents of the GoToSocial YAML config
|
| services.pgbackrest.settings | An attribute set of options as described in:
https://pgbackrest.org/configuration.html
All globally available options, i.e. all except stanza options, can be used
|
| services.forgejo.settings.server.PROTOCOL | Listen protocol. +unix means "over unix", not "in addition to."
|
| services.mbpfan.settings.general.low_temp | If temperature is below this, fans will run at minimum speed.
|
| services.mbpfan.settings.general.max_temp | If temperature is above this, fans will run at maximum speed.
|
| services.rosenpass.settings.peers.*.device | Name of the local WireGuard interface to use for this peer.
|
| services.privoxy.settings.enable-edit-actions | Whether the web-based actions file editor may be used.
|
| services.resolved.settings.Resolve.DNSOverTLS | Whether to use TLS encryption for DNS queries
|
| services.lidarr.settings.update.mechanism | which update mechanism to use
|
| services.sonarr.settings.update.mechanism | which update mechanism to use
|
| services.radarr.settings.update.mechanism | which update mechanism to use
|
| services.kanidm.server.settings.log_level | Log level of the server.
|
| services.anuko-time-tracker.settings.reportFooter | Defines whether to use a footer on reports.
|
| services.pid-fan-controller.settings.fans.*.minPwm | Minimum PWM value.
|
| services.pid-fan-controller.settings.fans.*.maxPwm | Maximum PWM value.
|
| services.keycloak.settings.hostname | The hostname part of the public URL used as base for
all frontend requests
|
| services.routinator.settings.retry | An integer value specifying the number of seconds an RTR client is requested to wait after it failed to receive a data set.
|
| services.firewalld.settings.ReloadPolicy | The policy during reload.
|
| services.birdwatcher.settings | birdwatcher configuration, for configuration options see the example on github
|
| services.meshtasticd.settings | The Meshtastic configuration file
|
| services.opensnitch.settings.LogLevel | Default log level from 0 to 4 (debug, info, important, warning,
error).
|
| services.sourcehut.settings."todo.sr.ht".notify-from | Outgoing email for notifications generated by users.
|
| services.slskd.settings.filters.search.request | Incoming search requests which match this filter are ignored.
|
| services.wg-access-server.settings.dns.enabled | Enable/disable the embedded DNS proxy server
|
| services.mautrix-discord.settings.logging | Logging configuration
|
| services.szurubooru.server.settings | Configuration to write to config.yaml
|
| services.homebridge.settings.bridge.name | Name of the homebridge
|
| services.suricata.settings.dpdk.eal-params.proc-type | dpdk eal-params.proc-type, see data plane development kit docs.
|
| services.filebrowser.settings.root | The directory where FileBrowser stores files.
|
| services.tor.settings.ExtraInfoStatistics | See torrc manual.
|
| services.mollysocket.settings.port | Listening port of the web server
|
| services.tor.settings.CookieAuthFileGroupReadable | See torrc manual.
|
| services.mollysocket.settings.host | Listening address of the web server
|
| services.taler.merchant.settings.merchant.DB | Plugin to use for the database.
|
| services.taler.exchange.settings.exchange.DB | Plugin to use for the database.
|
| services.reposilite.settings.basePath | Custom base path for this Reposilite instance
|
| services.grafana.settings.smtp.from_name | Name to be used as client identity for EHLO in SMTP dialog.
|
| services.sabnzbd.settings.misc.email_rss | Whether to send alerts for jobs added by RSS feeds
|
| services.pretix.settings.database.backend | Database backend to use
|
| services.sourcehut.settings."todo.sr.ht::mail".sock | Path for the lmtp daemon's unix socket
|
| services.suricata.settings.stats.stream-events | Add stream events as stats.
|
| services.kanidm.server.settings.tls_chain | TLS chain in pem format.
|
| services.filesender.settings.admin | UIDs (as per the configured saml_uid_attribute) of FileSender administrators
|
| services.bitmagnet.settings.postgres | PostgreSQL database configuration
|
| services.keycloak.settings | Configuration options corresponding to parameters set in
conf/keycloak.conf
|
| services.routinator.settings.log-level | A string value specifying the maximum log level for which log messages should be emitted
|
| services.displayManager.lemurs.settings | Configuration for lemurs, provided as a Nix attribute set and automatically
serialized to TOML
|
| nix.settings.system-features | The set of features supported by the machine
|
| services.homebridge.settings.bridge.port | The port homebridge listens on
|
| services.opengfw.settings.workers.udpMaxStreams | UDP max streams.
|
| services.mchprs.settings.bungeecord | Enable compatibility with
BungeeCord
|
| services.geoipupdate.settings | geoipupdate configuration options
|
| services.bookstack.settings.APP_KEY_FILE | The path to your appkey
|
| services.firewalld.settings.FlushAllOnReload | Whether to flush all runtime rules on a reload.
|
| services.public-inbox.settings.coderepo.<name>.cgitUrl | URL of a cgit instance
|
| services.suricata.settings.default-log-dir | The default logging directory
|
| services.postsrsd.settings.secrets-file | Path to the file containing the secret keys.
Secrets are passed using LoadCredential= on the systemd unit,
so this options is read-only
|
| services.grafana.settings.server.cert_key | Path to the certificate key file (if protocol is set to https or h2).
|
| services.tlsrpt.reportd.settings.fetchers | Comma-separated list of fetcher programs that retrieve collectd data.
|
| services.bluesky-pds.settings.PDS_REPORT_SERVICE_DID | DID of mod service
|
| services.sourcehut.settings."meta.sr.ht::settings".onboarding-redirect | Where to redirect new users upon registration.
|
| services.sourcehut.settings."hg.sr.ht".oauth-client-id | hg.sr.ht's OAuth client id for meta.sr.ht.
|
| services.etebase-server.settings.database.name | The database name.
|
| services.sourcehut.settings."meta.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."todo.sr.ht".api-origin | Origin URL for the API
|
| nix.settings.require-sigs | If enabled (the default), Nix will only download binaries from binary caches if
they are cryptographically signed with any of the keys listed in
nix.settings.trusted-public-keys
|
| services.radicle.ci.broker.settings.adapters | CI adapters
|
| services.routinator.settings.log-file | A string value containing the path to a file to which log messages will be appended if the log configuration value is set to file
|
| services.botamusique.settings | Your configuration.ini as a Nix attribute set
|
| services.zigbee2mqtt.settings | Your configuration.yaml as a Nix attribute set
|
| services.kubo.settings.Addresses.API | Multiaddr or array of multiaddrs describing the address to serve the local HTTP API on
|
| services.snapserver.settings.stream.port | Port to listen on for snapclient connections.
|
| services.librespeed.settings | LibreSpeed configuration written as Nix expression
|
| security.loginDefs.settings.UMASK | The file mode creation mask is initialized to this value.
|
| services.bitmagnet.settings.http_server | HTTP server settings
|
| services.firewalld.settings.CleanupOnExit | Whether to clean up firewall rules when firewalld stops.
|
| services.chhoto-url.settings.slug_style | The slug style to use for auto-generated URLs.
|
| services.syncthing.settings.folders.<name>.id | The ID of the folder
|
| services.syncthing.settings.devices.<name>.id | The device ID
|
| services.evremap.settings.dual_role | List of dual-role remappings that output different key sequences based on whether the
input key is held or tapped.
|
| services.biboumi.settings.log_level | Indicate what type of log messages to write in the logs.
0 is debug, 1 is info, 2 is warning, 3 is error.
|
| services.bluesky-pds.settings.PDS_REPORT_SERVICE_URL | URL of mod service
|
| services.gitea.settings.session.COOKIE_SECURE | Marks session cookies as "secure" as a hint for browsers to only send
them via HTTPS
|
| services.sourcehut.settings."meta.sr.ht::aliases" | Aliases for the client IDs of commonly used OAuth clients.
|
| services.hickory-dns.settings.directory | The directory in which hickory-dns should look for .zone files,
whenever zones aren't specified by absolute path.
|
| services.litellm.settings.router_settings | LiteLLM Router settings
|
| nix.settings.trusted-users | A list of names of users that have additional rights when
connecting to the Nix daemon, such as the ability to specify
additional binary caches, or to import unsigned NARs
|
| services.opensnitch.settings.Rules.Path | Path to the directory where firewall rules can be found and will
get stored by the NixOS module.
|
| services.umami.settings.COLLECT_API_ENDPOINT | Allows you to send metrics to a location different than the default /api/send.
|
| services.prometheus.exporters.script.settings.scripts | All settings expressed as an Nix attrset
|
| services.scrutiny.settings.web.influxdb.token | Authentication token for connecting to InfluxDB.
|
| security.loginDefs.settings.UID_MAX | Range of user IDs used for the creation of regular users by useradd or newusers.
|
| security.loginDefs.settings.UID_MIN | Range of user IDs used for the creation of regular users by useradd or newusers.
|
| services.xserver.displayManager.gdm.settings | Options passed to the gdm daemon
|
| services.mautrix-telegram.settings | config.yaml configuration as a Nix attribute set
|
| services.sourcehut.settings."man.sr.ht".oauth-client-id | man.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."git.sr.ht".oauth-client-id | git.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."hub.sr.ht".oauth-client-id | hub.sr.ht's OAuth client id for meta.sr.ht.
|
| services.listmonk.database.settings.smtp.*.port | Port for the SMTP server
|
| services.listmonk.database.settings.smtp.*.host | Hostname for the SMTP server
|
| services.journald.upload.settings.Upload.URL | The URL to upload the journal entries to
|
| services.postgresql.settings | PostgreSQL configuration
|
| services.sympa.settingsFile.<name>.source | Path of the source file.
|
| services.taler.settings.taler.CURRENCY_ROUND_UNIT | Smallest amount in this currency that can be transferred using the underlying RTGS
|
| services.opengfw.settings.replay.realtime | Whether the packets in the PCAP file should be replayed in "real time" (instead of as fast as possible).
|
| services.logrotate.settings.<name>.files | Single or list of files for which rules are defined
|
| programs.gnupg.agent.settings | Configuration for /etc/gnupg/gpg-agent.conf
|
| services.wastebin.settings.WASTEBIN_TITLE | Overrides the HTML page title
|
| services.wstunnel.clients.<name>.settings | Command line arguments to pass to wstunnel
|
| services.wstunnel.servers.<name>.settings | Command line arguments to pass to wstunnel
|
| services.postfix-tlspol.settings.dns.address | IP and port to your DNS resolver
|
| services.sourcehut.settings."builds.sr.ht".debug-host | Address to bind the debug server to.
|
| services.sourcehut.settings."builds.sr.ht".origin | URL builds.sr.ht is being served at (protocol://domain)
|
| services.sourcehut.settings."builds.sr.ht".debug-port | Port to bind the debug server to.
|
| services.knot-resolver.settings.network.listen | List of interfaces to listen to and its configuration.
|
| services.warpgate.settings.log.retention | How long Warpgate keep its logs.
|
| services.cryptpad.settings.installMethod | Install method is listed in telemetry if you agree to it through the consentToContact
setting in the admin panel.
|
| services.searx.settingsFile | The path of the Searx server settings.yml file
|
| services.swapspace.settings.swappath | Location where swapspace may create and delete swapfiles
|
| services.minidlna.settings.log_level | Defines the type of messages that should be logged and down to which level of importance.
|
| services.lasuite-docs.settings.DJANGO_SECRET_KEY_FILE | The path to the file containing Django's secret key
|
| services.lasuite-meet.settings.DJANGO_SECRET_KEY_FILE | The path to the file containing Django's secret key
|
| services.traefik.dynamic.files.<name>.settings | Dynamic configuration for Traefik, written in Nix.
This will be serialized to JSON (which is considered valid YAML) at build, and passed as part of the static file.
|
| services.szurubooru.server.settings.name | Name shown in the website title and on the front page.
|
| services.libeufin.nexus.settings.nexus-ebics.USER_ID | User ID of the EBICS subscriber
|
| nix.settings.allowed-users | A list of names of users (separated by whitespace) that are
allowed to connect to the Nix daemon
|
| services.moosefs.cgiserver.settings.DATA_PATH | Directory for lock files.
|
| services.hostapd.radios.<name>.settings | Extra configuration options to put at the end of global initialization, before defining BSSs
|
| services.matrix-appservice-irc.settings | Configuration for the appservice, see
https://github.com/matrix-org/matrix-appservice-irc/blob/4.0.0/config.sample.yaml
for supported values
|
| services.suricata.settings.stats.interval | The interval field (in seconds) controls the interval at
which stats are updated in the log.
|
| security.pam.rssh.settings | Options to pass to the pam_rssh module
|
| services.postfix.settings.master.<name>.command | A program name specifying a Postfix service/daemon process
|
| security.loginDefs.settings.GID_MAX | Range of group IDs used for the creation of regular groups by useradd, groupadd, or newusers.
|
| security.loginDefs.settings.GID_MIN | Range of group IDs used for the creation of regular groups by useradd, groupadd, or newusers.
|
| services.sourcehut.settings."lists.sr.ht".notify-from | Outgoing email for notifications generated by users.
|
| services.canaille.settings.CANAILLE_LDAP | Configuration for the LDAP backend
|
| services.bitmagnet.settings.postgres.user | User to connect as
|
| services.writefreely.settings.app.theme | The theme to apply.
|
| services.amule.settings.ExternalConnect.ECPort | TCP port for external connections, like remote control via amule-gui
|
| security.krb5.settings.include | Files to include in the Kerberos configuration.
|
| services.libeufin.nexus.settings.nexus-ebics.HOST_BASE_URL | URL of the EBICS server.
|
| services.anubis.instances.<name>.settings | Freeform configuration via environment variables for Anubis
|
| services.sourcehut.settings."sr.ht".global-domain | Global domain name.
|
| services.moosefs.metalogger.settings | Metalogger configuration options (mfsmetalogger.cfg).
|
| services.tor.settings.ServerTransportPlugin | See torrc manual.
|
| services.tor.settings.MaxClientCircuitsPending | See torrc manual.
|
| services.syncthing.settings.devices.<name>.name | The name of the device.
|
| services.clamav.fangfrisch.settings | fangfrisch configuration
|
| services.blackfire-agent.settings.server-id | Sets the server id used to authenticate with Blackfire
You can find your personal server-id at https://blackfire.io/my/settings/credentials
|
| services.biboumi.settings.password | The password used to authenticate the XMPP component to your XMPP server
|
| services.syncthing.settings.folders | Folders which should be shared by Syncthing
|
| services.veilid.settings.logging.system.enabled | Events of type 'system' will be logged.
|
| services.matrix-conduit.settings.global.port | The port Conduit will be running on
|
| services.syncthing.settings | Extra configuration options for Syncthing
|
| services.firezone.server.web.settings | Environment variables for this component of the Firezone server
|
| services.firezone.server.api.settings | Environment variables for this component of the Firezone server
|
| services.lokinet.settings.network.keyfile | The private key to persist address with
|
| services.bluesky-pds.settings.PDS_RATE_LIMITS_ENABLED | Enable rate limiting
|
| services.sourcehut.settings."builds.sr.ht".allow-free | Whether to enable nonpaying users to submit builds.
|
| services.opensnitch.settings.Stats.MaxStats | Max stats per item to keep in backlog.
|
| services.matrix-synapse.settings.database.name | The database engine name
|
| services.bitmagnet.settings.postgres.name | Database name to connect to
|
| services.sourcehut.settings."todo.sr.ht::mail".sock-group | The lmtp daemon will make the unix socket group-read/write
for users in this group.
|
| services.taler.merchant.settings.merchant.PORT | Port on which the HTTP server listens.
|
| services.taler.exchange.settings.exchange.PORT | Port on which the HTTP server listens.
|
| services.postgrest.settings.admin-server-port | Specifies the port for the admin server, which can be used for healthchecks.
https://docs.postgrest.org/en/stable/references/admin_server.html#admin-server
|
| services.scion.scion-dispatcher.settings | scion-dispatcher configuration
|
| services.postsrsd.settings.socketmap | Listener configuration in socket map format native to Postfix configuration.
|
| services.immich.settings.newVersionCheck.enabled | Check for new versions
|
| services.sftpgo.settings.smtp.encryption | Encryption scheme:
0: No encryption
1: TLS
2: STARTTLS
|
| services.tsidp.settings.useLocalTailscaled | Use local tailscaled instead of tsnet.
|
| services.stash.settings.theme_color | Sets the theme-color property in the UI
|
| services.keyd.keyboards.<name>.settings | Configuration, except ids section, that is written to /etc/keyd/.conf
|
| services.sabnzbd.settings.misc.https_key | Path to the TLS key for the web UI
|
| services.syncthing.settings.devices | Peers/devices which Syncthing should communicate with
|
| services.matrix-tuwunel.settings.global.port | The port(s) tuwunel will be running on
|
| hardware.apple.touchBar.settings | Configuration for tiny-dfr
|
| services.sourcehut.settings."hg.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.sourcehut.settings."lists.sr.ht".allow-new-lists | Whether to enable creation of new lists.
|
| services.sourcehut.settings."todo.sr.ht".oauth-client-id | todo.sr.ht's OAuth client id for meta.sr.ht.
|
| services.moosefs.cgiserver.settings.BIND_HOST | IP address to bind CGI server to.
|
| services.headscale.settings.oidc.pkce.method | PKCE method to use:
- plain: Use plain code verifier
- S256: Use SHA256 hashed code verifier (default, recommended)
|
| services.grafana.settings.server.http_port | Listening port.
|
| services.szurubooru.server.settings.smtp.port | Port of the SMTP server.
|
| services.sourcehut.settings."pages.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."lists.sr.ht".api-origin | Origin URL for the API
|
| services.sourcehut.settings."paste.sr.ht".api-origin | Origin URL for the API
|
| services.livekit.ingress.settings.redis.address | Address or hostname and port for redis connection
|
| services.szurubooru.server.settings.debug | Whether to generate server logs.
|
| services.neard.settings.General.DefaultPowered | Automatically turn an adapter on when being discovered.
|
| services.spacecookie.settings.log.level | Log level for the spacecookie service.
|
| services.warpgate.settings.postgres.enable | Whether to enable PostgreSQL listener.
|
| services.warpgate.settings.postgres.listen | Listen endpoint of PostgreSQL listener.
|
| services.firewalld.settings.LogDenied | Add logging rules right before reject and drop rules in the INPUT, FORWARD and OUTPUT chains for the default rules and also final reject and drop rules in zones for the configured link-layer packet type.
|
| services.xonotic.settings.maxplayers | Number of player slots on the server, including spectators.
|
| services.grafana.settings.database.host | Only applicable to MySQL or Postgres
|
| services.fediwall.settings.loadFederated | Load federated posts
|
| services.immich-kiosk.settings.immich_url | URL of the immich instance.
|
| services.bluesky-pds.settings.PDS_DATA_DIRECTORY | Directory to store state
|
| services.readarr.settings.update.mechanism | which update mechanism to use
|
| services.libeufin.bank.settings.libeufin-bank.PORT | The port on which libeufin-bank should listen.
|
| services.szurubooru.server.settings.smtp.user | User to connect to the SMTP server.
|
| services.evremap.settings.dual_role.*.tap | The key sequence that should be output when the input key is tapped
|
| services.postfix.settings.master.<name>.maxproc | The maximum number of processes to spawn for this service
|
| services.sslh.settings.protocols | List of protocols sslh will probe for and redirect
|
| services.sharkey.settings.mediaDirectory | Path to the folder where Sharkey stores uploaded media such as images and attachments.
|
| services.prometheus.xmpp-alerts.settings | Configuration for prometheus xmpp-alerts, see
https://github.com/jelmer/prometheus-xmpp-alerts/blob/master/xmpp-alerts.yml.example
for supported values.
|
| services.sourcehut.settings."pages.sr.ht".user-domain | Configures the user domain, if enabled
|
| services.go-csp-collector.settings.output-format | Define how the violation reports are formatted for output.
|
| services.reposilite.settings.cachedLogSize | Amount of messages stored in the cache logger.
|
| services.sourcehut.settings."git.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.snapserver.settings.tcp.enabled | Whether to enable the TCP JSON-RPC.
|
| services.nipap.settings.nipapd.foreground | Remain in foreground rather than forking to background.
|
| services.acme-dns.settings.logconfig.loglevel | Level to log on.
|
| services.legit.settings.meta.description | Website description.
|
| services.watchdogd.settings.interval | The kick interval, i.e. how often watchdogd(8) should reset the WDT timer.
|
| services.hedgedoc.settings.protocolUseSSL | Use https:// for all links
|
| services.litellm.settings.model_list | List of supported models on the server, with model-specific configs.
|
| services.postfix-tlspol.settings.server.address | Path or address/port where postfix-tlspol binds its socket to.
|
| services.matrix-conduit.settings.global.address | Address to listen on for connections by the reverse proxy/tls terminator.
|
| services.guacamole-client.settings | Configuration written to guacamole.properties.
The Guacamole web application uses one main configuration file called
guacamole.properties
|
| services.cryptpad.settings.websocketPort | Port for the websocket that needs to be separate
|
| services.filebrowser.settings.cache-dir | The directory where FileBrowser stores its cache.
|
| services.tor.settings.ControlPortFileGroupReadable | See torrc manual.
|
| services.reposilite.settings.enforceSsl | Whether to redirect all traffic to SSL.
|
| services.suricata.settings.threshold-file | Suricata threshold configuration file.
|
| services.tor.settings.ServerDNSDetectHijacking | See torrc manual.
|
| services.tor.settings.PaddingStatistics | See torrc manual.
|
| services.veilid.settings.logging.terminal.level | The minimum priority of terminal events to be logged.
|
| services.tlsrpt.reportd.settings.log_level | Level of log messages to emit.
|
| services.tlsrpt.fetcher.settings.log_level | Level of log messages to emit.
|
| services.suricata.settings.stats.decoder-events | Add decode events to stats
|
| services.postgrest.settings.server-host | Where to bind the PostgREST web server.
The admin server will also bind here, but potentially exposes sensitive information
|
| services.sabnzbd.settings.servers.<name>.timeout | Time, in seconds, to wait for a response before
attempting error recovery.
|
| services.opengfw.settings.workers.tcpTimeout | How long a connection is considered dead when no data is being transferred
|
| services.grafana.settings.smtp.password | Password used for authentication
|
| services.scrutiny.settings.web.influxdb.bucket | InfluxDB bucket in which to store data.
|
| services.tor.settings.ServerTransportPlugin.exec | Command of pluggable transport.
|
| services.gemstash.settings.base_path | Path to store the gem files and the sqlite database
|
| services.syncthing.settings.folders.<name>.type | Controls how the folder is handled by Syncthing
|
| services.saunafs.metalogger.settings | Contents of metalogger config file (see sfsmetalogger.cfg(5)).
|
| services.resolved.settings.Resolve.Domains | List of search domains used to complete unqualified name lookups.
|
| security.pam.u2f.settings.cue | By default pam-u2f module does not inform user
that he needs to use the u2f device, it just waits without a prompt
|
| services.vmalert.settings."datasource.url" | Datasource compatible with Prometheus HTTP API.
|
| services.fediwall.settings.hideSensitive | Hide sensitive (potentially NSFW) posts
|
| services.openssh.settings.X11Forwarding | Whether to allow X11 connections to be forwarded.
|
| services.scrutiny.collector.settings.host.id | Host ID for identifying/labelling groups of disks
|
| services.canaille.settings.CANAILLE.SMTP | SMTP configuration
|
| services.firefox-syncserver.settings.port | Port to bind to.
|
| services.opensearch.settings."cluster.name" | The name of the cluster.
|
| services.watchdogd.settings.filenr.enabled | Whether to enable watchdogd plugin filenr.
|
| services.postfix.settings.master.<name>.private | Whether the service's sockets and storage directory is restricted to
be only available via the mail system
|
| services.misskey.settings.redisForTimelines.port | The Redis port.
|
| services.misskey.settings.redisForTimelines.host | The Redis host.
|
| services.sympa.settingsFile.<name>.enable | Whether this file should be generated
|
| security.loginDefs.settings.SYS_UID_MAX | Range of user IDs used for the creation of system users by useradd or newusers.
|
| security.loginDefs.settings.SYS_UID_MIN | Range of user IDs used for the creation of system users by useradd or newusers.
|
| services.misskey.settings.redisForTimelines | ioredis options for timelines
|
| services.canaille.settings.CANAILLE_LDAP.BIND_PW | The LDAP bind password
|
| services.bitmagnet.settings.postgres.host | Address, hostname or Unix socket path of the database server
|
| services.immich.settings.server.externalDomain | Domain for publicly shared links, including http(s)://.
|
| services.tor.settings.DirAllowPrivateAddresses | See torrc manual.
|
| services.tor.settings.AuthDirSharedRandomness | See torrc manual.
|
| services.syncthing.settings.folders.<name>.label | The label of the folder.
|
| services.tor.settings.EnforceDistinctSubnets | See torrc manual.
|
| security.pam.u2f.settings.appid | By default pam-u2f module sets the application
ID to pam://$HOSTNAME
|
| services.scrutiny.settings.web.influxdb.scheme | URL scheme to use when connecting to InfluxDB.
|
| services.sabnzbd.settings.misc.email_from | 'From:' field for emails (needs to be an address)
|
| services.opensnitch.settings.Stats.MaxEvents | Max events to send to the GUI.
|
| services.pretalx.settings.filesystem.data | Base path for all other storage paths.
|
| services.neard.settings.General.ConstantPoll | Enable constant polling
|
| security.loginDefs.settings | Config options for the /etc/login.defs file, that defines
the site-specific configuration for the shadow password suite
|
| services.routinator.settings.expire | An integer value specifying the number of seconds an RTR client is requested to use a data set if it cannot get an update before throwing it away and continuing with no data at all.
|
| services.pretalx.settings.database.backend | Database backend to use
|
| services.printing.cups-pdf.instances.<name>.settings | Settings for a cups-pdf instance, see the descriptions in the template config file in the cups-pdf package
|
| services.szurubooru.server.settings.smtp.host | Host of the SMTP server used to send reset password.
|
| services.radicle.ci.broker.settings.adapters.<name>.env | Environment variables to add when running the adapter.
|
| services.reposilite.settings.sslEnabled | Whether to listen for encrypted connections on settings.sslPort.
|
| services.wgautomesh.settings.peers.*.pubkey | Wireguard public key of this peer.
|
| services.mbpfan.settings.general.high_temp | If temperature is above this, fan speed will gradually increase.
|
| services.watchdogd.settings.filenr.warning | The high watermark level
|
| services.healthchecks.settings.DB | Database engine to use.
|
| services.oncall.settings.oncall_host | FQDN for the Oncall instance.
|
| services.opensearch.settings."network.host" | Which port this service should listen on.
|
| services.nvme-rs.settings.email.smtp_server | SMTP server address
|
| services.evremap.settings.dual_role.*.hold | The key sequence that should be output when the input key is held
|
| services.waagent.settings.OS.RootDeviceScsiTimeout | Configures the SCSI timeout in seconds on the OS disk and data drives
|
| services.sourcehut.settings."meta.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.sourcehut.settings."todo.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.sourcehut.settings."lists.sr.ht".oauth-client-id | lists.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."pages.sr.ht".oauth-client-id | pages.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."paste.sr.ht".oauth-client-id | paste.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sabnzbd.settings.misc.email_full | Whether to send alerts for full disks
|
| services.snapserver.settings.http.enabled | Whether to enable the HTTP JSON-RPC.
|
| services.postsrsd.settings.separator | SRS tag separator used in generated sender addresses
|
| services.inadyn.settings.custom.<name>.password | Password for this DDNS provider
|
| services.vmalert.instances.<name>.settings | vmalert configuration, passed via command line flags
|
| services.opensnitch.settings.Server.LogFile | File to write logs to (use /dev/stdout to write logs to standard
output).
|
| services.stash.settings.stash_boxes | Stash-box facilitates automated tagging of scenes and performers based on fingerprints and filenames
|
| services.waagent.settings.ResourceDisk.SwapSizeMB | Specifies the size of the swap file in MiB (1024×1024 bytes)
|
| security.loginDefs.settings.SYS_GID_MAX | Range of group IDs used for the creation of system groups by useradd, groupadd, or newusers
|
| security.loginDefs.settings.SYS_GID_MIN | Range of group IDs used for the creation of system groups by useradd, groupadd, or newusers
|
| services.sslh.settings.transparent | Whether the services behind sslh (Apache, sshd and so on) will see the
external IP and ports as if the external world connected directly to
them.
|
| services.postgrest.settings.server-unix-socket | Unix domain socket where to bind the PostgREST web server.
|
| services.grafana.settings.server.cert_file | Path to the certificate file (if protocol is set to https or h2).
|
| services.watchdogd.settings.filenr.logmark | Whether to log current stats every poll interval.
|
| services.tor.settings.DormantCanceledByStartup | See torrc manual.
|
| services.tor.settings.DoSConnectionEnabled | See torrc manual.
|
| services.tor.settings.ServerDNSAllowNonRFC953Hostnames | See torrc manual.
|
| services.tor.settings.ExtORPortCookieAuthFileGroupReadable | See torrc manual.
|
| services.lidarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.sonarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.suricata.settings.unix-command.enabled | Enable unix-command socket.
|
| services.radarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.evremap.settings.dual_role.*.input | The key that should be remapped
|
| services.suricata.settings.vars.address-groups.HOME_NET | HOME_NET variable.
|
| services.matrix-synapse.settings.database.args.user | Username to connect with psycopg2, set to null
when using sqlite3.
|
| services.postfix.settings.main.relayhost | List of hosts to use for relaying outbound mail.
Putting the hostname in angled brackets, e.g. [relay.example.com], turns off MX and SRV lookups for the hostname.
https://www.postfix.org/postconf.5.html#relayhost
|
| services.anuko-time-tracker.settings.emailRequired | Defines whether an email is required for new registrations.
|
| services.matrix-synapse.settings.turn_uris | The public URIs of the TURN server to give to clients
|
| services.pretalx.settings.filesystem.logs | Path to the log directory, that pretalx logs message to.
|
| services.sourcehut.settings.mail.smtp-password | Outgoing SMTP password.
|
| services.grafana.settings.server.cdn_url | Specify a full HTTP URL address to the root of your Grafana CDN assets
|
| services.spacecookie.settings.root | The directory spacecookie should serve via gopher
|
| services.sourcehut.settings."pages.sr.ht".gemini-certs | An absolute file path (which should be outside the Nix-store)
to Gemini certificates.
|
| services.sftpgo.settings.webdavd.bindings.*.port | The port for serving WebDAV requests
|
| services.reposilite.settings.idleTimeout | Default idle timeout used by Jetty.
|
| services.stash.settings.stash_boxes.*.name | The name of the Stash Box
|
| services.wastebin.settings.WASTEBIN_MAX_BODY_SIZE | Number of bytes to accept for POST requests
|
| services.mautrix-whatsapp.settings | config.yaml configuration as a Nix attribute set
|
| services.gitlab.pages.settings.artifacts-server | API URL to proxy artifact requests to.
|
| services.typesense.settings.server.api-address | Address to which Typesense API service binds.
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs | List of inputs for this camera.
|
| services.wastebin.settings.WASTEBIN_BASE_URL | Base URL for the QR code display
|
| services.sourcehut.settings."builds.sr.ht".api-origin | Origin URL for the API
|
| services.suricata.settings.af-xdp.*.interface | af-xdp capture interface, see upstream docs.
|
| services.consul-template.instances.<name>.settings | Free-form settings written directly to the config.json file
|
| services.pid-fan-controller.settings.fans.*.cutoff | Whether to stop the fan when minPwm is reached.
|
| services.lasuite-docs.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.lasuite-meet.settings.DJANGO_ALLOWED_HOSTS | Comma-separated list of hosts that are able to connect to the server
|
| services.froide-govplan.settings.ALLOWED_HOSTS | A list of valid fully-qualified domain names (FQDNs) and/or IP
addresses that can be used to reach the Froide-Govplan service.
|
| services.nextcloud.settings.log_type | Logging backend to use.
systemd automatically adds the php-systemd extensions to services.nextcloud.phpExtraExtensions
|
| programs.starship.settings | Configuration included in starship.toml
|
| services.tor.settings.DoSCircuitCreationEnabled | See torrc manual.
|
| services.rosenpass.settings.verbosity | Verbosity of output produced by the service.
|
| services.spacecookie.settings.log.hide-ips | If enabled, spacecookie will hide personal
information of users like IP addresses from
log output.
|
| services.spacecookie.settings.log.enable | Whether to enable logging for spacecookie.
|
| services.snapserver.settings.tcp-control.port | Port to listen on for snapclient connections.
|
| services.spacecookie.settings.log.hide-time | If enabled, spacecookie will not print timestamps
at the beginning of every log line.
|
| services.suricata.settings.pcap.*.interface | pcap capture interface, see upstream docs.
|
| services.scrutiny.collector.settings.log.level | Log level for Scrutiny collector.
|
| services.opensnitch.settings.Firewall | Which firewall backend to use.
|
| services.etebase-server.settings.database.engine | The database engine to use.
|
| services.grafana-image-renderer.settings.server.addr | Listen address of the service.
|
| services.lemmy.settings.captcha.difficulty | The difficultly of the captcha to solve.
|
| services.suricata.settings.app-layer.error-policy | The error-policy setting applies to all app-layer parsers
|
| services.grafana.settings.users.home_page | Path to a custom home page
|
| services.suricata.settings.logging.outputs.file.type | Type of logfile.
|
| services.maubot.settings.server.public_url | Public base URL where the server is visible.
|
| services.privoxy.settings.filterfile | List of paths to Privoxy filter files
|
| services.doh-server.settings.upstream | Upstream DNS resolver
|
| services.openssh.settings.KexAlgorithms | Allowed key exchange algorithms
Uses the lower bound recommended in both
https://stribika.github.io/2015/01/04/secure-secure-shell.html
and
https://infosec.mozilla.org/guidelines/openssh#modern-openssh-67
|
| hardware.cpu.x86.msr.settings.allow-writes | Whether to allow writes to MSRs ("on") or not ("off").
|
| services.crowdsec.settings.simulation | Attributes inside the simulation.yaml file.
|
| services.chhoto-url.settings.slug_length | The length of auto-generated slugs.
|
| services.chhoto-url.settings.public_mode | Whether to enable public mode.
|
| services.pinnwand.settings.paste_size | Maximum size of a paste in bytes.
|
| services.headscale.settings.dns.magic_dns | Whether to use MagicDNS.
|
| services.blackfire-agent.settings.server-token | Sets the server token used to authenticate with Blackfire
You can find your personal server-token at https://blackfire.io/my/settings/credentials
|
| programs.spacefm.settings | The system-wide spacefm configuration
|
| services.sourcehut.settings."builds.sr.ht::worker".name | Listening address and listening port
of the build runner (with HTTP port if not 80).
|
| services.snapserver.settings.stream.source | One or multiple URIs to PCM input streams.
|
| services.bookstack.settings.DB_PASSWORD_FILE | The file containing your mysql/mariadb database password.
|
| services.rosenpass.settings.peers.*.endpoint | Endpoint of the remote Rosenpass peer.
|
| services.suricata.settings.outputs.*.<name>.enabled | Whether to enable .
|
| services.pgbouncer.settings.databases | Detailed information about PostgreSQL database definitions:
https://www.pgbouncer.org/config.html#section-databases
|
| services.nezha-agent.settings.temperature | Enable temperature monitoring.
|
| services.nezha-agent.settings.disable_nat | Disable NAT penetration.
|
| services.your_spotify.settings.PORT | The port of the api server
|
| services.writefreely.settings.server.port | The port WriteFreely should listen on.
|
| services.grafana.settings.server.http_addr | Listening address.
This setting intentionally varies from upstream's default to be a bit more secure by default.
|
| services.your_spotify.settings | Your Spotify Configuration
|
| services.sourcehut.settings."builds.sr.ht".shell | Scripts used to launch on SSH connection.
/usr/bin/master-shell on master,
/usr/bin/runner-shell on runner
|
| services.mchprs.settings.max_players | Maximum number of simultaneous players
|
| services.sourcehut.settings."lists.sr.ht".webhooks | The Redis connection used for the webhooks worker.
|
| services.inadyn.settings.provider.<name>.hostname | Hostname alias(es).
|
| services.ferretdb.settings.FERRETDB_SQLITE_URL | SQLite URI (directory) for 'sqlite' handler
|
| services.inadyn.settings.provider.<name>.username | Username for this DDNS provider.
|
| services.ferretdb.settings.FERRETDB_HANDLER | Backend handler
|
| services.sourcehut.settings."lists.sr.ht::worker".reject-url | Reject URL.
|
| services.hedgedoc.settings.allowGravatar | Whether to enable Libravatar as
profile picture source on your instance
|
| services.sourcehut.settings.objects.s3-access-key | Access key to the S3-compatible object storage service
|
| services.szurubooru.server.settings.domain | Full URL to the homepage of this szurubooru site (with no trailing slash).
|
| xdg.terminal-exec.settings | Configuration options for the Default Terminal Execution Specification
|
| services.umami.settings.DISABLE_TELEMETRY | Umami collects completely anonymous telemetry data in order help improve the application
|
| services.routinator.settings.rtr-listen | An array of string values each providing an address and port on which the RTR server should listen in TCP mode
|
| services.journald.remote.settings.Remote.SplitMode | With "host", a separate output file is used, based on the
hostname of the other endpoint of a connection
|
| services.botamusique.settings.server.port | Port of the mumble server to connect to.
|
| services.botamusique.settings.server.host | Hostname of the mumble server to connect to.
|
| services.livekit.ingress.settings.rtmp_port | TCP port for RTMP connections
|
| services.livekit.ingress.settings.whip_port | TCP port for WHIP connections
|
| services.reposilite.settings.debugEnabled | Whether to enable debug mode.
|
| services.tor.settings.ReachableAddresses | See torrc manual.
|
| services.sourcehut.settings."lists.sr.ht::worker".sock | Path for the lmtp daemon's unix socket
|
| services.sourcehut.settings."sr.ht".network-key | An absolute file path (which should be outside the Nix-store)
to a secret key to encrypt internal messages with
|
| services.forgejo.settings.session.COOKIE_SECURE | Marks session cookies as "secure" as a hint for browsers to only send
them via HTTPS
|
| services.firefly-iii.settings.DB_CONNECTION | The type of database you wish to use
|
| services.saunafs.metalogger.settings.DATA_PATH | Data storage directory
|
| services.prowlarr.settings.update.mechanism | which update mechanism to use
|
| services.whisparr.settings.update.mechanism | which update mechanism to use
|
| services.minidlna.settings.media_dir | Directories to be scanned for media files
|
| services.taler.merchant.settings.merchant.SERVE | Whether the HTTP server should listen on a UNIX domain socket ("unix") or on a TCP socket ("tcp").
|
| services.openbao.settings.listener.<name>.address | The TCP address or UNIX socket path to listen on.
|
| services.litellm.settings.general_settings | LiteLLM Server settings
|
| services.litellm.settings.litellm_settings | LiteLLM Module settings
|
| services.sourcehut.settings."builds.sr.ht".oauth-client-id | builds.sr.ht's OAuth client id for meta.sr.ht.
|
| services.sourcehut.settings."hg.sr.ht".oauth-client-secret | hg.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.watchdogd.settings.loadavg.enabled | Whether to enable watchdogd plugin loadavg.
|
| services.watchdogd.settings.meminfo.enabled | Whether to enable watchdogd plugin meminfo.
|
| services.hercules-ci-agent.settings.labels | A key-value map of user data
|
| services.szurubooru.server.settings.smtp.passFile | File containing the password associated to the given user for the SMTP server.
|
| services.healthchecks.settings.DB_NAME | Database name.
|
| services.filebrowser.settings.address | The address to listen on.
|
| services.scrutiny.settings.web.listen.basepath | If Scrutiny will be behind a path prefixed reverse proxy, you can override this
value to serve Scrutiny on a subpath.
|
| services.anuko-time-tracker.settings.weekendStartDay | This option defines which days are highlighted with weekend color.
6 means Saturday
|
| services.routinator.settings.http-listen | An array of string values each providing an address and port on which the HTTP server should listen
|
| services.wastebin.settings.WASTEBIN_CACHE_SIZE | Number of rendered syntax highlight items to cache
|
| services.buffyboard.settings.input.pointer | Enable or disable the use of a hardware mouse or other pointing device.
|
| services.parsedmarc.settings.mailbox.watch | Use the IMAP IDLE command to process messages as they arrive.
|
| services.suricata.settings.app-layer.protocols | app-layer protocols, see upstream docs.
|
| services.pinnwand.settings.paste_help | Raw HTML help text shown in the header area.
|
| services.headscale.settings.oidc.client_id | OpenID Connect client ID.
|
| services.tlsrpt.collectd.settings.log_level | Level of log messages to emit.
|
| services.moosefs.metalogger.settings.DATA_PATH | Directory for storing metalogger data.
|
| services.watchdogd.settings.filenr.interval | Amount of seconds between every poll.
|
| services.sabnzbd.settings.misc.html_login | Prompt for login with an html login mask if enabled,
otherwise prompt for basic auth (useful for SSO)
|
| services.firefly-iii-data-importer.settings | Options for firefly-iii data importer configuration
|
| services.tor.settings.ReachableORAddresses | See torrc manual.
|
| services.tor.settings.FetchHidServDescriptors | See torrc manual.
|
| services.pid-fan-controller.settings.heatSources | List of heat sources to be monitored.
|
| services.anuko-time-tracker.settings.multiorgMode | Defines whether users see the Register option in the menu of Time Tracker that allows them
to self-register and create new organizations (top groups).
|
| services.tor.relay.onionServices.<name>.settings.RendPostPeriod | See torrc manual.
|
| services.watchdogd.settings.loadavg.warning | The high watermark level
|
| services.watchdogd.settings.meminfo.warning | The high watermark level
|
| nix.settings.trusted-public-keys | List of public keys used to sign binary caches
|
| services.angrr.settings.profile-policies.<name>.enable | Whether to enable this angrr policy.
|
| services.matrix-synapse.settings.listeners.*.type | The type of the listener, usually http.
|
| services.misskey.settings.meilisearch | Meilisearch connection options.
|
| services.transmission.settings.rpc-port | The RPC port to listen to.
|
| services.postfix-tlspol.settings.server.prefetch | Whether to prefetch DNS records when the TTL of a cached record is about to expire.
|
| services.sabnzbd.settings.misc.https_cert | Path to the TLS certificate for the web UI
|
| services.postfix.settings.main.myhostname | The internet hostname of this mail system
|
| services.gemstash.settings.db_adapter | Which database type to use
|
| services.dsnet.settings.ExternalHostname | The hostname that clients should use to connect to this server
|
| services.sourcehut.settings."git.sr.ht".oauth-client-secret | git.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."hub.sr.ht".oauth-client-secret | hub.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."man.sr.ht".oauth-client-secret | man.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.lldap.settings.database_url | Database URL.
|
| services.lldap.settings.ldap_user_dn | Admin username
|
| services.stash.settings.plugins_path | Path to scrapers
|
| services.sftpgo.settings.ftpd.bindings.*.address | Network listen address
|
| services.syncthing.settings.folders.<name>.path | The path to the folder which should be shared
|
| services.watchdogd.settings.loadavg.logmark | Whether to log current stats every poll interval.
|
| services.watchdogd.settings.meminfo.logmark | Whether to log current stats every poll interval.
|
| services.angrr.settings.profile-policies.<name>.keep-since | Retention period for the GC roots in this profile.
|
| services.matrix-synapse.settings.listeners.*.port | The port to listen for HTTP(S) requests on.
|
| services.matrix-synapse.settings.listeners.*.mode | File permissions on the UNIX domain socket.
|
| services.readarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.warpgate.settings.recordings.path | Path to store session recordings.
|
| services.open-web-calendar.settings.ALLOWED_HOSTS | The hosts that the Open Web Calendar permits
|
| services.authelia.instances.<name>.settings.theme | The theme to display.
|
| services.tor.settings.KeyDirectoryGroupReadable | See torrc manual.
|
| services.umurmur.settings.welcometext | Welcome message for connected clients.
|
| services.tor.settings.ReachableDirAddresses | See torrc manual.
|
| services.moosefs.chunkserver.settings | Chunkserver configuration options (mfschunkserver.cfg).
|
| services.xonotic.settings.net_address | The address Xonotic will listen on.
|
| services.buffyboard.settings.theme.default | Selects the default theme on boot
|
| services.grafana.settings.users.login_hint | Text used as placeholder text on login page for login/username input.
|
| services.mchprs.settings.chat_format | How to format chat message interpolating username
and message with curly braces
|
| services.cryptpad.settings.blockDailyCheck | Disable telemetry
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs.*.path | Stream URL
|
| services.minidlna.settings.wide_links | Set this to yes to allow symlinks that point outside user-defined media_dir.
|
| services.nextcloud-whiteboard-server.settings | Settings to configure backend server
|
| services.firezone.server.domain.settings | Environment variables for this component of the Firezone server
|
| services.botamusique.settings.bot.comment | Comment displayed for the bot.
|
| services.logrotate.settings.<name>.priority | Order of this logrotate block in relation to the others
|
| services.geoipupdate.settings.AccountID | Your MaxMind account ID.
|
| services.healthchecks.settings.DEBUG | Enable debug mode.
|
| services.lldap.settings.ldap_base_dn | Base DN for LDAP.
|
| services.opensnitch.settings.Ebpf.ModulesPath | Configure eBPF modules path
|
| services.libeufin.nexus.settings.nexus-ebics.CURRENCY | Name of the fiat currency.
|
| services.headscale.settings.prefixes.v6 | Each prefix consists of either an IPv4 or IPv6 address,
and the associated prefix length, delimited by a slash
|
| services.headscale.settings.prefixes.v4 | Each prefix consists of either an IPv4 or IPv6 address,
and the associated prefix length, delimited by a slash
|
| services.suricata.settings.logging.outputs.file.level | Loglevel for logs written to the logfile.
|
| services.snapserver.settings.http.doc_root | Path to serve from the HTTP servers root.
|
| services.sourcehut.settings."lists.sr.ht".posting-domain | Posting domain.
|
| services.biboumi.settings.identd_port | The TCP port on which to listen for identd queries.
|
| services.public-inbox.settings.publicinbox | public inboxes
|
| services.suricata.settings.unix-command | Unix command socket that can be used to pass commands to Suricata
|
| services.reposilite.settings.hostname | The hostname to bind to
|
| services.suricata.settings.unix-command.filename | Filename for unix-command socket.
|
| services.misskey.settings.meilisearch.ssl | Whether to connect via SSL.
|
| services.sourcehut.settings."git.sr.ht".post-update-script | A post-update script which is installed in every git repo
|
| services.peering-manager.settings.ALLOWED_HOSTS | A list of valid fully-qualified domain names (FQDNs) and/or IP
addresses that can be used to reach the peering manager service.
|
| services.pid-fan-controller.settings.interval | Interval between controller cycles in milliseconds.
|
| services.tuned.settings.profile_dirs | Directories to search for profiles, separated by , or ;.
|
| services.tor.settings.ControlSocketsGroupWritable | See torrc manual.
|
| services.rkvm.server.settings.certificate | TLS certificate path.
This should be generated with rkvm-certificate-gen.
|
| services.rkvm.client.settings.certificate | TLS ceritficate path.
This should be generated with rkvm-certificate-gen.
|
| services.sabnzbd.settings.servers.<name>.priority | Priority of this servers
|
| services.sabnzbd.settings.servers.<name>.required | In case of connection failures, wait for the
server to come back online instead of skipping
it.
|
| services.headscale.settings.database.type | Database engine to use
|
| services.anubis.instances.<name>.settings.TARGET | The reverse proxy target that Anubis is protecting
|
| services.zeronsd.servedNetworks.<name>.settings.token | Path to a file containing the API Token for ZeroTier Central.
|
| services.reposilite.settings.keyPath | Path to the .jsk KeyStore or paths to the PKCS#8 certificate and private key, separated by a space (see example)
|
| services.acme-dns.settings.database.connection | Database connection string.
|
| services.sourcehut.settings."lists.sr.ht::worker".sock-group | The lmtp daemon will make the unix socket group-read/write
for users in this group.
|
| services.matrix-tuwunel.settings.global.address | Addresses (IPv4 or IPv6) to listen on for connections by the reverse proxy/tls terminator
|
| services.crowdsec-firewall-bouncer.settings.mode | Firewall mode to use.
|
| services.sourcehut.settings."meta.sr.ht".welcome-emails | Whether to enable sending stock sourcehut welcome emails after signup.
|
| boot.initrd.network.ifstate.settings | Content of IfState's initrd configuration file
|
| services.easytier.instances.<name>.settings.dhcp | Automatically determine the IPv4 address of this peer based on
existing peers on network.
|
| services.sourcehut.settings.objects.s3-secret-key | An absolute file path (which should be outside the Nix-store)
to the secret key of the S3-compatible object storage service.
|
| services.sourcehut.settings."todo.sr.ht".oauth-client-secret | todo.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.authelia.instances.<name>.settings.log.level | Level of verbosity for logs.
|
| services.parsedmarc.settings.mailbox.delete | Delete messages after processing them, instead of archiving them.
|
| services.pretalx.settings.filesystem.static | Path to the directory that contains static files.
|
| services.routinator.settings.refresh | An integer value specifying the number of seconds Routinator should wait between consecutive validation runs in server mode
|
| services.sourcehut.settings."git.sr.ht".outgoing-domain | Outgoing domain.
|
| services.sourcehut.settings."todo.sr.ht::mail".posting-domain | Posting domain.
|
| services.misskey.settings.meilisearch.host | The Meilisearch host.
|
| services.misskey.settings.meilisearch.port | The Meilisearch port.
|
| services.lldap.settings.ldap_user_pass | Password for default admin password
|
| services.headscale.settings.oidc.pkce.enabled | Enable or disable PKCE (Proof Key for Code Exchange) support
|
| services.slskd.settings.retention.files.complete | Lifespan of completely downloaded files in minutes.
|
| services.veilid.settings.logging.terminal.enabled | Events of type 'terminal' will be logged.
|
| services.sabnzbd.settings.servers.<name>.optional | In case of connection failures, temporarily
disable this server. (See sabnzbd's documentation
for usage guides).
|
| services.suricata.settings.vars.address-groups.DNP3_SERVER | DNP3_SERVER variable.
|
| services.suricata.settings.vars.address-groups.DNP3_CLIENT | DNP3_CLIENT variable.
|
| services.grafana-image-renderer.settings.browser.path | Path to the executable of the chromium to use.
|
| services.angrr.settings.temporary-root-policies | Policies for temporary GC roots(e.g. result and direnv).
|
| services.wstunnel.clients.<name>.settings.http-headers | Custom headers to send in the upgrade request
|
| services.hercules-ci-agent.settings.secretsJsonPath | Path to a JSON file containing secrets for effects
|
| services.tor.settings.DataDirectoryGroupReadable | See torrc manual.
|
| services.tor.settings.HiddenServiceNonAnonymousMode | See torrc manual.
|
| services.tor.settings.ConstrainedSockets | See torrc manual.
|
| services.libeufin.nexus.settings.nexus-ebics.PARTNER_ID | Partner ID of the EBICS subscriber
|
| services.grafana.settings.server.root_url | This is the full URL used to access Grafana from a web browser
|
| services.headscale.settings.database.sqlite.path | Path to the sqlite3 database file.
|
| services.radicle.ci.broker.settings.triggers.*.filters | Trigger filter.
|
| services.radicle.ci.broker.settings.triggers.*.adapter | Adapter name.
|
| services.reposilite.settings.database | Database connection string
|
| services.bonsaid.settings.*.event_name | Name of the event which should trigger this transition when received by bonsaid
|
| services.anuko-time-tracker.settings.email.smtpPasswordFile | Path to file containing the MTA authentication password.
|
| services.omnom.settings.activitypub.pubkey | ActivityPub public key
|
| services.vmalert.instances.<name>.settings.rule | Path to the files with alerting and/or recording rules.
|
| services.misskey.settings.meilisearch.apiKey | The Meilisearch API key.
|
| services.maubot.settings.homeservers.<name>.url | Client-server API URL
|
| services.radicle.ci.broker.settings.report_dir | Directory where HTML and JSON report pages are written.
|
| i18n.inputMethod.fcitx5.settings.addons | The addon configures in conf folder in ini format with global sections
|
| services.archisteamfarm.bots.<name>.settings | Additional settings that are documented here.
|
| services.matrix-synapse.settings.listeners.*.tls | Whether to enable TLS on the listener socket.
This option will be ignored for UNIX domain sockets.
|
| services.ocsinventory-agent.settings.tag | Tag for the generated inventory.
|
| services.grafana-image-renderer.settings.service.port | The TCP port to use for the rendering server.
|
| services.yggdrasil.settings.PrivateKeyPath | Path to the private key file on the host system
|
| services.pds.settings.PDS_BLOBSTORE_DISK_LOCATION | Store blobs at this location, set to null to use e.g
|
| services.umurmur.settings.certificate | Path to your SSL certificate
|
| services.umurmur.settings.private_key | Path to your SSL key
|
| services.saunafs.chunkserver.settings | Contents of chunkserver config file (see sfschunkserver.cfg(5)).
|
| services.hickory-dns.settings.listen_port | Port to listen on (applies to all listen addresses).
|
| services.transmission.settings.peer-port | The peer port to listen for incoming connections.
|
| services.watchdogd.settings.filenr.critical | The critical watermark level
|
| services.homebridge.settings.platforms | Homebridge Platforms
|
| services.sftpgo.settings.sftpd.bindings.*.address | Network listen address
|
| services.sftpgo.settings.httpd.bindings.*.address | Network listen address
|
| services.listmonk.database.settings.smtp.*.enabled | Whether to enable this SMTP server for listmonk.
|
| services.firezone.server.settingsSecret | This is a convenience option which allows you to set secret values for
environment variables by specifying a file which will contain the value
at runtime
|
| services.grafana.settings.smtp.skip_verify | Verify SSL for SMTP server.
|
| services.suwayomi-server.settings.server.localSourcePath | Path to the local source folder.
|
| services.hercules-ci-agent.settings.baseDirectory | State directory (secrets, work directory, etc) for agent
|
| services.tor.settings.ExtendAllowPrivateAddresses | See torrc manual.
|
| services.grafana.settings.database.ssl_mode | For Postgres, use either disable, require or verify-full
|
| services.postfix.settings.main.mynetworks | List of trusted remote SMTP clients, that are allowed to relay mail
|
| services.waagent.settings.ResourceDisk.EnableSwap | If enabled, the agent creates a swap file (/swapfile) on the resource disk
and adds it to the system swap space
|
| services.swapspace.settings.cooldown | Duration (roughly in seconds) of the moratorium on swap allocation that is instated if disk space runs out, or the cooldown time after a new swapfile is successfully allocated before swapspace will consider deallocating swap space again
|
| services.sourcehut.settings."hg.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.stash.settings.stash_boxes.*.apikey | Stash Box API key
|
| services.waagent.settings.ResourceDisk.MountPoint | This option specifies the path at which the resource disk is mounted
|
| services.wastebin.settings.WASTEBIN_ADDRESS_PORT | Address and port to bind to
|
| services.slskd.settings.shares.directories | Paths to shared directories
|
| systemd.tmpfiles.settings | Declare systemd-tmpfiles rules to create, delete, and clean up volatile
and temporary files and directories
|
| services.tinc.networks.<name>.hostSettings.<name>.settings | Configuration for this host
|
| services.nebula-lighthouse-service.settings | Configuration for nebula-lighthouse-service.
|
| services.pid-fan-controller.settings.heatSources.*.name | Name of the heat source.
|
| services.wgautomesh.settings.peers.*.address | Wireguard address of this peer (a single IP address, multiple
addresses or address ranges are not supported).
|
| services.yggdrasil.settings.AllowedPublicKeys | List of peer public keys to allow incoming peering connections from
|
| services.suricata.settings.vars.address-groups.ENIP_CLIENT | ENIP_CLIENT variable.
|
| services.suricata.settings.vars.address-groups.ENIP_SERVER | ENIP_SERVER variable.
|
| services.frigate.settings.cameras.<name>.ffmpeg.inputs.*.roles | List of roles for this stream
|
| services.healthchecks.settingsFile | Environment variables which are read by healthchecks (local)_settings.py
|
| services.easytier.instances.<name>.settings.peers | Peers to connect initially
|
| services.sourcehut.settings."meta.sr.ht::billing".enabled | Whether to enable the billing system.
|
| services.omnom.settings.smtp.send_timeout | Send timeout duration in seconds.
|
| services.watchdogd.settings.loadavg.interval | Amount of seconds between every poll.
|
| services.watchdogd.settings.meminfo.interval | Amount of seconds between every poll.
|
| services.anubis.defaultOptions.settings.POLICY_FNAME | The policy file to use
|
| services.pretix.settings.memcached.location | The host:port combination or the path to the UNIX socket of a memcached instance
|
| services.pocket-id.settings.ANALYTICS_DISABLED | Whether to disable analytics
|
| services.zeronsd.servedNetworks.<name>.settings.domain | Domain under which ZeroTier records will be available.
|
| services.headscale.settings.server_url | The url clients will connect to.
|
| services.tor.settings.HiddenServiceStatistics | See torrc manual.
|
| services.tor.settings.PublishServerDescriptor | See torrc manual.
|
| services.tor.settings.FetchServerDescriptors | See torrc manual.
|
| services.suricata.settings.reference-config-file | Suricata reference configuration file.
|
| services.mautrix-meta.instances.<name>.settings | config.yaml configuration as a Nix attribute set
|
| services.sourcehut.settings."git.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."man.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."hub.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.schleuder.settings.keyserver | Key server from which to fetch and update keys
|
| services.authelia.instances.<name>.settings | Your Authelia config.yml as a Nix attribute set
|
| services.epgstation.settings.socketioPort | Socket.io port for EPGStation to listen on
|
| services.transmission.settings.watch-dir | Watch a directory for torrent files and add them to transmission.
|
| services.suricata.settings.logging.outputs.file.format | Logformat for logs written to the logfile.
|
| services.suricata.settings.logging.outputs.file.enable | Whether to enable logging to file.
|
| services.suricata.settings.logging.outputs.syslog.type | Type of logs send to syslog.
|
| services.languagetool.settings.cacheSize | Number of sentences cached.
|
| services.maubot.settings.api_features | API feature switches.
|
| services.sourcehut.settings."lists.sr.ht".oauth-client-secret | lists.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."paste.sr.ht".oauth-client-secret | paste.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.sourcehut.settings."pages.sr.ht".oauth-client-secret | pages.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.misskey.settings.meilisearch.scope | The search scope.
|
| services.reposilite.settings.ioThreadPool | The IO thread pool handles all tasks that may benefit from non-blocking IO. (min: 2)
Because most tasks are redirected to IO thread pool, it might be a good idea to keep it at least equal to web thread pool.
|
| services.opensnitch.settings.DefaultAction | Default action whether to block or allow application internet
access.
|
| services.canaille.settings.PREFERRED_URL_SCHEME | The url scheme by which canaille will be served.
|
| services.postfix.settings.master.<name>.privileged | |
| services.printing.cups-pdf.instances.<name>.settings.Spool | spool directory
|
| services.hercules-ci-agent.settings.workDirectory | The directory in which temporary subdirectories are created for task state
|
| services.szurubooru.server.settings.secretFile | File containing a secret used to salt the users' password hashes and generate filenames for static content.
|
| services.reposilite.settings.webThreadPool | Maximum amount of threads used by the core thread pool. (min: 5)
The web thread pool handles the first few steps of incoming HTTP connections, tasks are redirected as soon as possible to the IO thread pool.
|
| services.tor.settings.CacheDirectoryGroupReadable | See torrc manual.
|
| services.maubot.settings.homeservers | Known homeservers
|
| <imports = [ pkgs.php.services.default ]>.php-fpm.settings.log_level | Error log level.
|
| services.sourcehut.settings.mail.pgp-privkey | An absolute file path (which should be outside the Nix-store)
to an OpenPGP private key
|
| services.misskey.settings.meilisearch.index | Meilisearch index to use.
|
| services.filesender.settings.site_url | Site URL
|
| services.easytier.instances.<name>.settings.ipv4 | IPv4 cidr address of this peer in the virtual network
|
| services.hercules-ci-agent.settings.binaryCachesPath | Path to a JSON file containing binary cache secret keys
|
| services.opensnitch.settings.Server.Address | Unix socket path (unix:///tmp/osui.sock, the "unix:///" part is
mandatory) or TCP socket (192.168.1.100:50051).
|
| services.mackerel-agent.settings.diagnostic | Whether to enable collecting memory usage for the agent itself.
|
| services.matrix-appservice-irc.settings.ircService | IRC bridge configuration
|
| services.public-inbox.settings.publicinbox.css | The local path name of a CSS file for the PSGI web interface.
|
| services.authelia.instances.<name>.settings.log.format | Format the logs are written as.
|
| services.kanidm.server.settings.bindaddress | Address/port combination the webserver binds to.
|
| services.angrr.settings.profile-policies.<name>.keep-latest-n | Keep the latest N GC roots in this profile.
|
| services.syncthing.settings.folders.<name>.enable | Whether to share this folder
|
| services.suricata.settings.vars.address-groups.DC_SERVERS | DC_SERVERS variable.
|
| services.evremap.settings.device_name | The name of the device that should be remapped
|
| services.privoxy.settings.actionsfile | List of paths to Privoxy action files
|
| services.fastnetmon-advanced.settings | Extra configuration options to declaratively load into FastNetMon Advanced
|
| services.suwayomi-server.settings.server.downloadAsCbz | Download chapters as .cbz files.
|
| services.prowlarr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.whisparr.settings.log.analyticsEnabled | Send Anonymous Usage Data
|
| services.inadyn.settings.provider.<name>.password | Password for this DDNS provider
|
| services.ocsinventory-agent.settings.ca | Path to CA certificates file in PEM format, for server
SSL certificate validation.
|
| services.filebrowser.settings.database | The path to FileBrowser's Bolt database.
|
| services.opensnitch.settings.ProcMonitorMethod | Which process monitoring method to use.
|
| services.postfix.settings.main.smtp_tls_CAfile | File containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA certificates
|
| services.waagent.settings.ResourceDisk.FileSystem | The file system type for the resource disk
|
| services.sourcehut.settings.objects.s3-upstream | Configure the S3-compatible object storage service.
|
| services.sourcehut.settings."meta.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."todo.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.suricata.settings.af-packet.*.interface | af-packet capture interface, see upstream docs reagrding tuning.
|
| services.botamusique.settings.bot.username | Name the bot should appear with.
|
| services.bitmagnet.settings.dht_server.port | DHT listen port
|
| services.tlsrpt.collectd.settings.socketmode | Permissions on the UNIX socket.
|
| services.szurubooru.server.settings.data_dir | Path to the static files.
|
| services.sourcehut.settings."builds.sr.ht::worker".timeout | Max build duration
|
| services.radicle.ci.broker.settings.adapters.<name>.command | Adapter command to run.
|
| services.firewalld.settings.CleanupModulesOnExit | Whether to unload all firewall-related kernel modules when firewalld stops.
|
| services.suricata.settings.vars.address-groups.AIM_SERVERS | AIM_SERVERS variable.
|
| services.suricata.settings.vars.address-groups.DNS_SERVERS | DNS_SERVERS variable.
|
| services.suricata.settings.vars.address-groups.SQL_SERVERS | SQL_SERVERS variable.
|
| services.parsedmarc.settings.imap.password | The IMAP server password
|
| services.parsedmarc.settings.smtp.password | The SMTP server password
|
| services.printing.cups-pdf.instances.<name>.settings.Out | output directory;
${HOME} will be expanded to the user's home directory,
${USER} will be expanded to the user name.
|
| services.hddfancontrol.settings | Parameter-sets for each instance of hddfancontrol.
|
| services.libeufin.nexus.settings.nexus-ebics.BANK_PUBLIC_KEYS_FILE | Filesystem location where Nexus should store the bank public keys.
|
| services.szurubooru.server.settings.data_url | Full URL to the data endpoint.
|
| services.warpgate.settings.recordings.enable | Whether to enable session recording.
|
| services.anubis.defaultOptions.settings.SERVE_ROBOTS_TXT | Whether to serve a default robots.txt that denies access to common AI bots by name and all other
bots by wildcard.
|
| i18n.inputMethod.fcitx5.settings.inputMethod | The input method configure in profile file in ini format.
|
| services.logrotate.settings.<name>.frequency | How often to rotate the logs
|
| services.anubis.instances.<name>.settings.BIND | The address that Anubis listens to
|
| services.tor.settings.AuthDirHasIPv6Connectivity | See torrc manual.
|
| services.anubis.defaultOptions.settings.BIND_NETWORK | The network family that Anubis should bind to
|
| services.omnom.settings.activitypub.privkey | ActivityPub private key
|
| services.suricata.settings.outputs | Configure the type of alert (and other) logging you would like
|
| services.canaille.settings.CANAILLE.SMTP.PASSWORD | SMTP Password
|
| services.kanidm.unix.settings.hsm_pin_path | Path to a HSM pin.
|
| services.wastebin.settings.WASTEBIN_HTTP_TIMEOUT | Maximum number of seconds a request can be processed until wastebin responds with 408
|
| services.libeufin.nexus.settings.nexus-ebics.BANK_DIALECT | Name of the following combination: EBICS version and ISO20022
recommendations that Nexus would honor in the communication with the
bank
|
| services.tinyproxy.settings.Anonymous | If an Anonymous keyword is present, then anonymous proxying is enabled
|
| nix.settings.auto-optimise-store | If set to true, Nix automatically detects files in the store that have
identical contents, and replaces them with hard links to a single copy
|
| services.immichframe.settings.Accounts | Accounts configuration, multiple are permitted
|
| services.epgstation.settings.mirakurunPath | URL to connect to Mirakurun.
|
| services.opensearch.settings."discovery.type" | The type of discovery to use.
|
| services.anubis.instances.<name>.settings.POLICY_FNAME | The policy file to use
|
| services.szurubooru.server.settings.show_sql | Whether to show SQL in server logs.
|
| services.tlsrpt.collectd.settings.socketname | Path at which the UNIX socket will be created.
|
| services.gitlab.pages.settings.internal-gitlab-server | Internal GitLab server used for API requests, useful
if you want to send that traffic over an internal load
balancer
|
| services.suricata.settings.stats.decoder-events-prefix | Decoder event prefix in stats
|
| services.watchdogd.settings.loadavg.critical | The critical watermark level
|
| services.watchdogd.settings.meminfo.critical | The critical watermark level
|
| services.garage.settings.metadata_dir | The metadata directory, put this on a fast disk (e.g
|
| services.fastnetmon-advanced.traffic_db.settings | Additional settings for /etc/fastnetmon/traffic_db.conf
|
| services.wstunnel.servers.<name>.settings.restrict-to.*.port | The port.
|
| services.wstunnel.servers.<name>.settings.restrict-to.*.host | The hostname.
|
| services.canaille.settings.CANAILLE_OIDC.JWT.PRIVATE_KEY | JWT private key
|
| services.saunafs.chunkserver.settings.DATA_PATH | Directory for chunck meta data
|
| services.draupnir.settings.homeserverUrl | Base URL of the Matrix homeserver that provides the Client-Server API.
|
| services.epgstation.settings.encodeProcessNum | The maximum number of processes that EPGStation would allow to run
at the same time for encoding or streaming videos.
|
| services.glitchtip.settings.GLITCHTIP_DOMAIN | The URL under which GlitchTip is externally reachable.
|
| services.homebridge.settings.platforms.*.name | Name of the platform
|
| services.tor.settings.PublishHidServDescriptors | See torrc manual.
|
| services.tor.settings.MaxAdvertisedBandwidth | See torrc manual.
|
| services.opensearch.settings."transport.port" | The port to listen on for transport traffic.
|
| services.ocsinventory-agent.settings.debug | Whether to enable debug mode.
|
| services.prometheus.exporters.ping.settings | Configuration for ping_exporter, see
https://github.com/czerwonk/ping_exporter
for supported values.
|
| services.waagent.settings.AutoUpdate.UpdateToLatestVersion | Whether or not to enable auto-update of the Extension Handler.
|
| services.globalprotect.settings | GlobalProtect-openconnect configuration
|
| services.adguardhome.settings | AdGuard Home configuration
|
| services.keycloak.settings.http-relative-path | The path relative to / for serving
resources.
In versions of Keycloak using Wildfly (<17),
this defaulted to /auth
|
| services.sourcehut.settings."git.sr.ht::api".internal-ipnet | Set of IP subnets which are permitted to utilize internal API
authentication
|
| services.mautrix-discord.settings.homeserver | fullDataDiration
|
| services.vault-agent.instances.<name>.settings.pid_file | Path to use for the pid file.
|
| security.loginDefs.settings.TTYPERM | The terminal permissions: the login tty will be owned by the TTYGROUP group,
and the permissions will be set to TTYPERM
|
| services.sourcehut.settings."builds.sr.ht".oauth-client-secret | builds.sr.ht's OAuth client secret for meta.sr.ht.
|
| services.moosefs.chunkserver.settings.DATA_PATH | Directory for lock files and other runtime data.
|
| services.snapserver.settings.tcp-control.enabled | Whether to enable the TCP JSON-RPC.
|
| services.suricata.settings.dpdk.interfaces | See upstream docs: docs/capture-hardware/dpdk and docs/configuration/suricata-yaml.html#data-plane-development-kit-dpdk.
|
| services.swapspace.settings.freetarget | Percentage of free space swapspace should aim for when adding swapspace
|
| services.wgautomesh.settings.interface | Wireguard interface to manage (it is NOT created by wgautomesh, you
should use another NixOS option to create it such as
networking.wireguard.interfaces.wg0 = {...};).
|
| services.wgautomesh.settings.peers.*.endpoint | Bootstrap endpoint for connecting to this Wireguard peer if no
other address is known or none are working.
|
| services.suricata.settings.vars.address-groups.SMTP_SERVERS | SMTP_SERVERS variable.
|
| services.suricata.settings.vars.address-groups.HTTP_SERVERS | HTTP_SERVERS variable.
|
| services.minidlna.settings.enable_tivo | Support for streaming .jpg and .mp3 files to a TiVo supporting HMO.
|
| services.ocsinventory-agent.settings | Configuration for /etc/ocsinventory-agent/ocsinventory-agent.cfg
|
| services.listmonk.database.settings.smtp.*.tls_type | Type of TLS authentication with the SMTP server
|
| services.dendrite.settings.sync_api.search.enabled | Whether to enable Dendrite's full-text search engine.
|
| services.matrix-appservice-irc.settings.database | Configuration for the database
|
| services.snapserver.settings.tcp-streaming.port | Port to listen on for snapclient connections.
|
| services.warpgate.settings.http.certificate | Path to HTTPS listener certificate.
|
| services.anuko-time-tracker.settings.defaultCurrency | Defines a default currency symbol for new groups
|
| services.matrix-synapse.settings.listeners | List of ports that Synapse should listen on, their purpose and their configuration
|
| services.journald.upload.settings.Upload.ServerKeyFile | SSL key in PEM format
|
| networking.ifstate.settings | Content of IfState's configuration file
|
| services.mautrix-discord.settings.appservice | Appservice configuration
|
| security.loginDefs.settings.DEFAULT_HOME | Indicate if login is allowed if we can't cd to the home directory.
|
| services.sabnzbd.settings.misc.cache_limit | Size of the RAM cache, in bytes (prefixes supported)
|
| services.tor.settings.FetchUselessDescriptors | See torrc manual.
|
| services.sourcehut.settings."pages.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."lists.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."paste.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.suricata.settings.logging.default-log-level | The default log level: can be overridden in an output section
|
| services.oncall.settings.db.conn.require_auth | Whether authentication is required to access the web app.
|
| services.sourcehut.settings."sr.ht".service-key | An absolute file path (which should be outside the Nix-store)
to a key used for encrypting session cookies
|
| services.reposilite.settings.keyPassword | Plaintext password used to unlock the Java KeyStore set in services.reposilite.settings.keyPath
|
| services.hickory-dns.settings.zones.*.zone_type | One of:
- "Primary" (the master, authority for the zone).
- "Secondary" (the slave, replicated from the primary).
- "External" (a cached zone that queries other nameservers)
|
| services.bitmagnet.settings.postgres.password | Password for database user
|
| services.amule.settings.ExternalConnect.ECPassword | MD5 hash of the password, obtainaible with echo "<password>" | md5sum | cut -d ' ' -f 1
|
| services.matrix-synapse.settings.presence.enabled | Whether to enable presence tracking
|
| services.waagent.settings.ResourceDisk.MountOptions | This option specifies disk mount options to be passed to the mount -o command
|
| services.opensnitch.settings.Audit.AudispSocketPath | Configure audit socket path
|
| services.waagent.settings.ResourceDisk.Format | If set to true, waagent formats and mounts the resource disk that the platform provides,
unless the file system type in `ResourceDisk
|
| services.opengfw.settings.workers.tcpMaxBufferedPagesTotal | TCP max total buffered pages.
|
| services.quickwit.settings.rest.listen_port | The port to listen on for HTTP REST traffic.
|
| services.geoipupdate.settings.EditionIDs | List of database edition IDs
|
| services.printing.cups-pdf.instances.<name>.settings.AnonDirName | path for anonymously created PDF files
|
| services.opengfw.settings.workers.tcpMaxBufferedPagesPerConn | TCP max total bufferd pages per connection.
|
| boot.initrd.systemd.settings.Manager | Options for the global systemd service manager used in initrd
|
| services.taler.exchange.settings.exchange.CURRENCY | The currency which the exchange will operate with
|
| services.tor.settings.ExitPolicyRejectLocalInterfaces | See torrc manual.
|
| services.tor.settings.ConnDirectionStatistics | See torrc manual.
|
| services.gitea-actions-runner.instances.<name>.settings | Configuration for act_runner daemon
|
| services.matrix-continuwuity.settings | Generates the continuwuity.toml configuration file
|
| security.pam.u2f.settings.origin | By default pam-u2f module sets the origin
to pam://$HOSTNAME
|
| services.sourcehut.settings."meta.sr.ht::api".internal-ipnet | Set of IP subnets which are permitted to utilize internal API
authentication
|
| services.geoipupdate.settings.LicenseKey | A file containing the MaxMind license key
|
| services.anubis.instances.<name>.settings.SERVE_ROBOTS_TXT | Whether to serve a default robots.txt that denies access to common AI bots by name and all other
bots by wildcard.
|
| services.rosenpass.settings.public_key | Path to a file containing the public key of the local Rosenpass peer
|
| services.rosenpass.settings.secret_key | Path to a file containing the secret key of the local Rosenpass peer
|
| services.etebase-server.settings.global.media_root | The media directory.
|
| services.suricata.settings.vars.address-groups.MODBUS_CLIENT | MODBUS_CLIENT variable
|
| services.suricata.settings.vars.address-groups.MODBUS_SERVER | MODBUS_SERVER variable.
|
| services.matrix-synapse.settings.listeners.*.path | Unix domain socket path to bind this listener to.
|
| services.stash.settings.stash.*.excludevideo | Whether to exclude video files from being scanned into Stash
|
| services.stash.settings.stash.*.excludeimage | Whether to exclude image files from being scanned into Stash
|
| services.anubis.instances.<name>.settings.BIND_NETWORK | The network family that Anubis should bind to
|
| services.stash.settings.scrapers_path | Path to scrapers
|
| services.stash.settings.blobs_storage | Where to store blobs
|
| services.slskd.settings.global.upload.speed_limit | Total upload speed limit.
|
| services.invoiceplane.sites.<name>.settings | Structural InvoicePlane configuration
|
| services.nextcloud-spreed-signaling.settings | Declarative configuration
|
| services.vault-agent.instances.<name>.settings.template | Template section of vault-agent
|
| services.suricata.settings.logging.outputs.syslog.format | Logformat for logs send to syslog.
|
| services.suricata.settings.logging.outputs.syslog.enable | Whether to enable logging to syslog.
|
| services.tor.settings.GuardfractionFile | See torrc manual.
|
| services.grafana.settings.security.admin_user | Default admin username.
|
| services.kerberos_server.settings | Settings for the kerberos server of choice
|
| services.nezha-agent.settings.report_delay | The interval between system status reportings
|
| services.suricata.settings.dpdk | Data Plane Development Kit is a framework for fast packet processing in data plane applications running on a wide variety of CPU architectures
|
| services.headscale.settings.database.postgres.user | Database user.
|
| services.headscale.settings.database.postgres.name | Database name.
|
| services.sftpgo.settings.webdavd.bindings.*.address | Network listen address
|
| services.draupnir.settings.rawHomeserverUrl | Public base URL of the Matrix homeserver that provides the Client-Server API when using the Draupnir's
Report forwarding feature.
When using Pantalaimon, do not set this to the Pantalaimon URL!
|
| services.slskd.settings.soulseek.description | The user description for the Soulseek network.
|
| services.slskd.settings.soulseek.listen_port | The port on which to listen for incoming connections.
|
| services.warpgate.settings.mysql.certificate | Path to MySQL listener certificate.
|
| services.netbird.server.dashboard.settings | An attribute set that will be used to substitute variables when building the dashboard
|
| services.spacecookie.settings.hostname | The hostname the service is reachable via
|
| services.suricata.settings.logging.default-log-format | The default output format
|
| services.syncthing.settings.options.relaysEnabled | When true, relays will be connected to and potentially used for device to device connections.
|
| services.scrutiny.collector.settings.api.endpoint | Scrutiny app API endpoint for sending metrics to.
|
| services.pgbackrest.stanzas.<name>.settings | An attribute set of options as described in:
https://pgbackrest.org/configuration.html
All options can be used
|
| services.stash.settings.preview_audio | Include audio stream in previews
|
| services.headscale.settings.database.postgres.host | Database host address.
|
| services.headscale.settings.database.postgres.port | Database host port.
|
| services.sourcehut.settings."builds.sr.ht::worker".bind-address | HTTP bind address for serving local build information/monitoring.
|
| services.firewalld.settings.NftablesCounters | Whether to add a counter to every nftables rule.
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.P | K_p of PID controller.
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.D | K_d of PID controller.
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.I | K_i of PID controller.
|
| services.suricata.settings.vars.address-groups.EXTERNAL_NET | EXTERNAL_NET variable.
|
| services.grafana.settings.database.password | The database user's password (not applicable for sqlite3)
|
| services.wastebin.settings.WASTEBIN_DATABASE_PATH | Path to the sqlite3 database file
|
| services.grafana.settings.smtp.from_address | Address used when sending out emails.
|
| services.crowdsec.settings.lapi.credentialsFile | The LAPI credential file to use.
|
| services.crowdsec.settings.capi.credentialsFile | The CAPI credential file to use.
|
| hardware.bluetooth.settings | Set configuration for system-wide bluetooth (/etc/bluetooth/main.conf)
|
| services.dependency-track.settings."alpine.oidc.client.id" | Defines the client ID to be used for OpenID Connect
|
| services.tlsrpt.reportd.settings.http_script | Call to an HTTPS client, that accepts the URL on the commandline and the request body from stdin.
|
| services.sourcehut.settings."builds.sr.ht".migrate-on-upgrade | Whether to enable automatic migrations on package upgrade.
|
| services.sourcehut.settings."meta.sr.ht::billing".stripe-public-key | Public key for Stripe
|
| services.suwayomi-server.settings.server.systemTrayEnabled | Whether to enable a system tray icon, if possible.
|
| services.tor.settings.ClientRejectInternalAddresses | See torrc manual.
|
| services.sourcehut.settings."pages.sr.ht::api".internal-ipnet | Set of IP subnets which are permitted to utilize internal API
authentication
|
| services.sabnzbd.settings.misc.enable_https | Whether to enable HTTPS for the web UI
|
| services.sabnzbd.settings.misc.email_server | SMTP server for email alerts (server:host)
|
| services.crowdsec-firewall-bouncer.settings.api_url | URL of the local API.
|
| services.bonsaid.settings.*.transitions | List of transitions out of this state
|
| security.auditd.plugins.<name>.settings | Plugin-specific config file to link to /etc/audit/.conf
|
| services.transmission.settings.umask | Sets transmission's file mode creation mask
|
| services.suricata.settings.logging.outputs.file.filename | Filename of the logfile.
|
| security.agnos.settings.accounts.*.email | Email associated with this account.
|
| services.suwayomi-server.settings.server.basicAuthUsername | The username value that you have to provide when authenticating.
|
| services.healthchecks.settings.SECRET_KEY_FILE | Path to a file containing the secret key.
|
| services.suricata.settings.pcap-file.checksum-checks | Possible values are:
- yes: checksum validation is forced
- no: checksum validation is disabled
- auto: Suricata uses a statistical approach to detect when
checksum off-loading is used. (default)
Warning: 'checksum-validation' must be set to yes to have checksum tested.
|
| services.wstunnel.servers.<name>.settings.restrict-to | Restrictions on the connections that the server will accept
|
| services.suwayomi-server.settings.server.basicAuthEnabled | Whether to enable basic access authentication for Suwayomi-Server
|
| services.ferretdb.settings.FERRETDB_TELEMETRY | Enable or disable basic telemetry
|
| services.transmission.settings.utp-enabled | Whether to enable Micro Transport Protocol (µTP).
|
| services.stash.settings.calculate_md5 | Whether to calculate MD5 checksums for scene video files
|
| services.maubot.settings.server.ui_base_path | The base path for the UI.
|
| services.tor.settings.DoSRefuseSingleHopClientRendezvous | See torrc manual.
|
| programs.openvpn3.netcfg.settings | Options stored in /etc/openvpn3/netcfg.json configuration file
|
| services.grafana.settings.database.cache_mode | For sqlite3 only.
Shared cache setting used for connecting to the database.
|
| services.nextcloud-spreed-signaling.settings.mcu.type | The type of MCU to use
|
| services.syncthing.settings.folders.<name>.devices | The devices this folder should be shared with
|
| services.matrix-synapse.settings.database.args.database | Name of the database when using the psycopg2 backend,
path to the database location when using sqlite3.
|
| services.reposilite.settings.defaultFrontend | Whether to enable the default included frontend with a dashboard.
|
| services.nvme-rs.settings.email.smtp_username | SMTP username
|
| services.crab-hole.settings.blocklist.allow_list | List of allowlists
|
| services.taler.exchange.settings.exchange.MASTER_PUBLIC_KEY | Used by the exchange to verify information signed by the offline system.
|
| services.angrr.settings.temporary-root-policies.<name>.ignore-prefixes | List of path prefixes to ignore
|
| services.grafana.provision.alerting.rules.settings | Grafana rules configuration in Nix
|
| services.moosefs.cgiserver.settings.GUISERV_LISTEN_PORT | Port for GUI server to listen on.
|
| services.authelia.instances.<name>.settingsFiles | Here you can provide authelia with configuration files or directories
|
| services.routinator.settings.repository-dir | The path where the collected RPKI data is stored.
|
| services.rosenpass.settings.peers.*.public_key | Path to a file containing the public key of the remote Rosenpass peer.
|
| services.firewalld.settings.NftablesTableOwner | If enabled, the generated nftables rule set will be owned exclusively by firewalld
|
| services.pid-fan-controller.settings.fans.*.heatPressureSrcs | Heat pressure sources affected by the fan.
|
| services.stash.settings.stash_boxes.*.endpoint | URL to the Stash Box graphql api
|
| services.waagent.settings.Provisioning.Agent | Which provisioning agent to use.
|
| services.tor.settings.ClientDNSRejectInternalAddresses | See torrc manual.
|
| services.tor.settings.DisableDebuggerAttachment | See torrc manual.
|
| services.tor.settings.DormantTimeoutDisabledByIdleStreams | See torrc manual.
|
| services.ocsinventory-agent.settings.local | If specified, the OCS Inventory Agent will run in offline mode
and the resulting inventory file will be stored in the specified path.
|
| services.grafana.settings.server.socket_gid | GID where the socket should be set when protocol=socket
|
| services.grafana-image-renderer.settings.rendering.args | List of CLI flags passed to chromium.
|
| services.suricata.settings.vars.address-groups.TELNET_SERVERS | TELNET_SERVERS variable.
|
| services.grafana.settings.server.socket_mode | Mode where the socket should be set when protocol=socket
|
| services.dependency-track.settings."alpine.ldap.enabled" | Defines if LDAP will be used for user authentication
|
| services.anuko-time-tracker.settings.defaultLanguage | Defines Anuko Time Tracker default language
|
| services.bitmagnet.settings.http_server.port | HTTP server listen port
|
| services.zeronsd.servedNetworks.<name>.settings.wildcard | Whether to serve a wildcard record for ZeroTier Nodes.
|
| services.hercules-ci-agent.settings.clusterJoinTokenPath | Location of the cluster-join-token.key file
|
| services.suricata.settings.logging.outputs.console.enable | Whether to enable logging to console.
|
| services.moosefs.cgiserver.settings.GUISERV_LISTEN_HOST | IP address to bind GUI server to (* means any).
|
| services.pretix.settings.pretix.registration | Whether to allow registration of new admin users.
|
| services.syncthing.settings.options.localAnnouncePort | The port on which to listen and send IPv4 broadcast announcements to.
|
| boot.initrd.systemd.tmpfiles.settings | Similar to systemd.tmpfiles.settings but the rules are
only applied by systemd-tmpfiles before initrd-switch-root.target
|
| services.dependency-track.settings."alpine.oidc.enabled" | Defines if OpenID Connect will be used for user authentication
|
| services.sabnzbd.secretFiles | Path to a list of ini file containing confidential settings such as credentials
|
| services.slskd.settings.retention.files.incomplete | Lifespan of incomplete downloading files in minutes.
|
| services.listmonk.database.settings.smtp.*.max_conns | Maximum number of simultaneous connections, defaults to 1
|
| services.dependency-track.settings."alpine.database.url" | Specifies the JDBC URL to use when connecting to the database.
|
| services.pretalx.settings.files.upload_limit | Maximum file upload size in MiB.
|
| services.printing.cups-pdf.instances.<name>.settings.GhostScript | location of GhostScript binary
|
| services.sourcehut.settings."sr.ht".environment | Values other than "production" adds a banner to each page.
|
| services.angrr.settings.temporary-root-policies.<name>.enable | Whether to enable this angrr policy.
|
| services.suricata.settings.logging.default-output-filter | A regex to filter output
|
| services.dependency-track.settings."alpine.oidc.issuer" | Defines the issuer URL to be used for OpenID Connect
|
| services.nextcloud.settings.loglevel | Log level value between 0 (DEBUG) and 4 (FATAL).
-
0 (debug): Log all activity.
-
1 (info): Log activity such as user logins and file activities, plus warnings, errors, and fatal errors.
-
2 (warn): Log successful operations, as well as warnings of potential problems, errors and fatal errors.
-
3 (error): Log failed operations and fatal errors.
-
4 (fatal): Log only fatal errors that cause the server to stop.
|
| services.sourcehut.settings."hg.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.dendrite.settings.media_api.base_path | Storage path for uploaded media.
|
| services.sourcehut.settings."meta.sr.ht::billing".stripe-secret-key | An absolute file path (which should be outside the Nix-store)
to a secret key for Stripe
|
| services.maubot.settings.database_opts | Additional arguments for asyncpg.create_pool() or sqlite3.connect()
|
| security.loginDefs.settings.TTYGROUP | The terminal permissions: the login tty will be owned by the TTYGROUP group,
and the permissions will be set to TTYPERM
|
| services.transmission.settings.message-level | Set verbosity of transmission messages.
|
| services.engelsystem.settings | Options to be added to config.php, as a nix attribute set
|
| services.suwayomi-server.settings.server.extensionRepos | URL of repositories from which the extensions can be installed.
|
| services.nextcloud-spreed-signaling.settings.nats.url | URL of one or more NATS backends to use
|
| services.transmission.settings.download-dir | Directory where to download torrents.
|
| services.vmalert.instances.<name>.settings."notifier.url" | Prometheus Alertmanager URL
|
| services.libeufin.bank.settings.libeufin-bank.CURRENCY | The currency under which the libeufin-bank should operate
|
| services.journald.remote.settings.Remote.ServerKeyFile | A path to a SSL secret key file in PEM format
|
| services.angrr.settings.profile-policies.<name>.keep-booted-system | Whether to keep the last booted system generation
|
| services.sourcehut.settings."hub.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."git.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."man.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.angrr.settings.temporary-root-policies.<name>.period | Retention period for the GC roots matched by this policy.
|
| services.angrr.settings.temporary-root-policies.<name>.path-regex | Regex pattern to match the GC root path.
|
| services.easytier.instances.<name>.settings.hostname | Hostname shown in peer list and web console.
|
| services.evdevremapkeys.settings | config.yaml for evdevremapkeys
|
| services.ocsinventory-agent.settings.server | The URI of the OCS Inventory server where to send the inventory file
|
| services.transmission.settings.rpc-bind-address | Where to listen for RPC connections
|
| services.mchprs.settings.auto_redpiler | Use redpiler automatically
|
| services.warpgate.settings.database_url | Database connection string
|
| services.simplesamlphp.<name>.settings | Configuration options used by SimpleSAMLphp
|
| services.firewalld.settings.FirewallBackend | The firewall backend implementation
|
| services.listmonk.database.settings.messengers | List of messengers, see: https://github.com/knadh/listmonk/blob/master/models/settings.go#L64-L74 for options.
|
| services.logind.settings.Login.KillUserProcesses | Specifies whether the processes of a user should be killed
when the user logs out
|
| services.libeufin.nexus.settings.nexus-ebics.CLIENT_PRIVATE_KEYS_FILE | Filesystem location where Nexus should store the subscriber private keys.
|
| services.sslh.settings.verbose-connections | Where to log connections information
|
| services.canaille.settings.CANAILLE_SQL.DATABASE_URI | The SQL server URI
|
| i18n.inputMethod.fcitx5.settings.globalOptions | The global options in config file in ini format.
|
| services.sourcehut.settings."builds.sr.ht::worker".buildlogs | Path to write build logs.
|
| services.authelia.instances.<name>.settings.server.address | The address to listen on.
|
| services.slskd.settings.directories.downloads | Directory where downloaded files are stored.
|
| services.bluesky-pds.settings.PDS_BLOBSTORE_DISK_LOCATION | Store blobs at this location, set to null to use e.g
|
| services.syncthing.settings.options.urAccepted | Whether the user has accepted to submit anonymous usage data
|
| services.nextcloud.settings.mail_domain | The return address that you want to appear on emails sent by the Nextcloud server, for example nc-admin@example.com, substituting your own domain, of course.
|
| services.grafana-image-renderer.settings.rendering.width | Width of the PNG used to display the alerting graph.
|
| services.suwayomi-server.settings.server.basicAuthPasswordFile | The password file containing the value that you have to provide when authenticating.
|
| services.matrix-appservice-irc.settings.database.engine | Which database engine to use
|
| services.angrr.settings.temporary-root-policies.<name>.filter | External filter program to further filter GC roots matched by this policy.
|
| services.reposilite.settings.bypassExternalCache | Add cache bypass headers to responses from /api/* to avoid issues with proxies such as Cloudflare.
|
| services.epgstation.settings.clientSocketioPort | Socket.io port that the web client is going to connect to
|
| services.angrr.settings.temporary-root-policies.<name>.ignore-prefixes-in-home | Path prefixes to ignore under home directory
|
| services.healthchecks.settings.ALLOWED_HOSTS | The host/domain names that this site can serve.
|
| services.sabnzbd.settings.misc.email_endjob | Whether to send emails on job completion
|
| services.sourcehut.settings."meta.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."todo.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.tlsrpt.reportd.settings.contact_info | Contact information embedded into the reports.
|
| services.nextcloud-spreed-signaling.settings.https.key | Path to the private key used for the HTTPS listener
|
| services.transmission.settings.watch-dir-enabled | Whether to enable the
services.transmission.settings.watch-dir.
|
| services.homebridge.settings.accessories | Homebridge Accessories
|
| services.hostapd.radios.<name>.networks.<name>.settings | Extra configuration options to put at the end of this BSS's defintion in the
hostapd.conf for the associated interface
|
| services.etebase-server.settings.global.static_root | The directory for static files.
|
| services.listmonk.database.settings."bounce.mailboxes" | List of bounce mailboxes
|
| services.matrix-appservice-irc.settings.ircService.servers | IRC servers to connect to
|
| services.mchprs.settings.view_distance | Maximal distance (in chunks) between players and loaded chunks
|
| security.loginDefs.settings.ENCRYPT_METHOD | This defines the system default encryption algorithm for encrypting passwords.
|
| services.grafana.provision.alerting.rules.settings.groups | List of rule groups to import or update.
|
| services.opensnitch.settings.InterceptUnknown | Whether to intercept spare connections.
|
| services.tor.settings.BridgeAuthoritativeDir | See torrc manual.
|
| services.zeronsd.servedNetworks.<name>.settings.log_level | Log Level.
|
| services.grafana.settings.server.enable_gzip | Set this option to true to enable HTTP compression, this can improve transfer speed and bandwidth utilization
|
| services.suricata.settings.logging.outputs.syslog.facility | Facility to log to.
|
| services.transmission.settings.peer-port-random-low | The minimal peer port to listen to for incoming connections
when services.transmission.settings.peer-port-random-on-start is enabled.
|
| services.homebridge.settings.description | Description of the homebridge instance.
|
| services.transmission.settings.peer-port-random-on-start | Randomize the peer port.
|
| services.umurmur.settings.channel_links | Channel tree definitions.
|
| services.anuko-time-tracker.settings.exportDecimalDuration | Defines whether time duration values are decimal in CSV and XML data
exports (1.25 vs 1:15).
|
| services.firewalld.settings.StrictForwardPorts | If enabled, the generated destination NAT (DNAT) rules will NOT accept traffic that was DNAT'd by other entities, e.g. docker
|
| nix.settings.sandbox | If set, Nix will perform builds in a sandboxed environment that it
will set up automatically for each build
|
| services.pid-fan-controller.settings.heatSources.*.pidParams.setPoint | Set point of the controller in °C.
|
| services.dendrite.settings.sync_api.search.language | The language most likely to be used on the server - used when indexing, to
ensure the returned results match expectations
|
| services.immichframe.settings.Accounts.*.ApiKeyFile | File containing an API key to talk to the Immich server
|
| services.snapserver.settings.tcp-streaming.enabled | Whether to enable streaming via TCP.
|
| services.grafana.settings.users.hidden_users | This is a comma-separated list of usernames
|
| services.grafana-image-renderer.settings.service.logging.level | The log-level of the grafana-image-renderer.service-unit.
|
| services.slskd.settings.global.download.speed_limit | Total upload download limit
|
| services.sabnzbd.settings.servers.<name>.displayname | Human-friendly description of the server
|
| services.sourcehut.settings.webhooks.private-key | An absolute file path (which should be outside the Nix-store)
to a base64-encoded Ed25519 key for signing webhook payloads
|
| services.netbird.server.management.settings | Configuration of the netbird management server
|
| services.radicle.ci.adapters.native.instances.<name>.settings | Configuration of radicle-native-ci
|
| services.anubis.defaultOptions.settings.DIFFICULTY | The difficulty required for clients to solve the challenge
|
| services.matrix-synapse.settings.log_config | The file that holds the logging configuration.
|
| services.grafana.settings.security.admin_email | The email of the default Grafana Admin, created on startup.
|
| services.pinnwand.settings.database_uri | Database URI compatible with SQLAlchemy
|
| services.angrr.settings.profile-policies.<name>.keep-current-system | Whether to keep the current system generation
|
| services.sabnzbd.settings.servers.<name>.connections | Number of parallel connections permitted by
the server.
|
| networking.wireless.iwd.settings | Options passed to iwd
|
| services.omnom.settings.server.secure_cookie | Whether to limit cookies to a secure channel.
|
| services.transmission.settings.peer-port-random-high | The maximum peer port to listen to for incoming connections
when services.transmission.settings.peer-port-random-on-start is enabled.
|
| services.pid-fan-controller.settings.fans.*.wildcardPath | Wildcard path of the hwmon pwm file
|
| services.matrix-synapse.settings.report_stats | Whether or not to report anonymized homeserver usage statistics.
|
| services.radicle.ci.adapters.native.instances.<name>.settings.log | File where radicle-native-ci should write the run log.
|
| services.sabnzbd.settings.servers.<name>.ssl_verify | Level of TLS verification
|
| services.etebase-server.settings.global.secret_file | The path to a file containing the secret
used as django's SECRET_KEY.
|
| services.grafana.settings.database.log_queries | Set to true to log the sql calls and execution times
|
| services.dendrite.settings.global.server_name | The domain name of the server, with optional explicit port
|
| services.sourcehut.settings."pages.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."paste.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.sourcehut.settings."lists.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.immichframe.settings.Accounts.*.ApiKey | API key to talk to the Immich server
|
| security.agnos.settings.accounts | A list of ACME accounts
|
| services.grafana-image-renderer.settings.rendering.height | Height of the PNG used to display the alerting graph.
|
| services.reposilite.settings.databaseThreadPool | Maximum amount of concurrent connections to the database. (one per thread)
Embedded databases (sqlite, h2) do not support truly concurrent connections, so the value will always be 1 if they are used.
|
| services.firewalld.settings.IndividualCalls | Whether to use individual -restore calls to apply changes to the firewall
|
| services.matrix-tuwunel.settings.global.server_name | The server_name is the name of this server
|
| services.matrix-conduit.settings.global.server_name | The server_name is the name of this server
|
| services.ferretdb.settings.FERRETDB_POSTGRESQL_URL | PostgreSQL URL for 'pg' handler
|
| services.nextcloud.settings."profile.enabled" | Makes user-profiles globally available under nextcloud.tld/u/user.name
|
| services.syncthing.settings.devices.<name>.autoAcceptFolders | Automatically create or share folders that this device advertises at the default path
|
| services.printing.cups-pdf.instances.<name>.settings.Anonuser | User for anonymous PDF creation
|
| security.krb5.settings.includedir | Directories containing files to include in the Kerberos configuration.
|
| services.your_spotify.settings.MONGO_ENDPOINT | The endpoint of the Mongo database.
|
| services.grafana.provision.dashboards.settings | Grafana dashboard configuration in Nix
|
| services.matrix-synapse.settings.server_name | The domain name of the server, with optional explicit port
|
| services.grafana.settings.paths.provisioning | Folder that contains provisioning config files that grafana will apply on startup and while running
|
| services.nextcloud-spreed-signaling.settings.grpc.listen | IP and port to listen on for GRPC requests
|
| services.syncthing.settings.options.limitBandwidthInLan | Whether to apply bandwidth limits to devices in the same broadcast domain as the local device.
|
| services.wgautomesh.settings.gossip_port | wgautomesh gossip port, this MUST be the same number on all nodes in
the wgautomesh network.
|
| services.headscale.settings.tls_key_path | Path to key for already created certificate.
|
| services.swapspace.settings.max_swapsize | Greatest allowed size for individual swapfiles
|
| services.swapspace.settings.min_swapsize | Smallest allowed size for individual swapfiles
|
| services.maubot.settings.plugin_databases | Plugin database settings
|
| services.system76-scheduler.settings.cfsProfiles.enable | Tweak CFS latency parameters when going on/off battery
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceSingleHopMode | See torrc manual.
|
| services.matrix-appservice-irc.settings.homeserver | Homeserver configuration
|
| services.nextcloud-spreed-signaling.settings.app.debug | Set to "true" to install pprof debug handlers
|
| services.headscale.settings.dns.nameservers.global | List of nameservers to pass to Tailscale clients.
|
| nix.settings.substituters | List of binary cache URLs used to obtain pre-built binaries
of Nix packages
|
| services.anubis.defaultOptions.settings.WEBMASTER_EMAIL | If set, shows a contact email address when rendering error pages
|
| services.tuned.settings.dynamic_tuning | Whether to enable dynamic tuning.
|
| services.pretix.settings.pretix.instance_name | The name of this installation.
|
| services.umurmur.settings.max_bandwidth | Maximum bandwidth (in bits per second) that clients may send
speech at.
|
| services.anubis.defaultOptions.settings.METRICS_BIND_NETWORK | The network family that the metrics server should bind to
|
| services.grafana.provision.alerting.rules.settings.groups.*.name | Name of the rule group
|
| services.dependency-track.settings."alpine.database.driver" | Specifies the JDBC driver class to use.
|
| services.olivetin.settings.ListenAddressSingleHTTPFrontend | The address to listen on for the internal "microproxy" frontend.
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceMaxStreams | See torrc manual.
|
| services.matrix-appservice-discord.settings | config.yaml configuration as a Nix attribute set
|
| services.prometheus.exporters.fritz.settings.devices | Fritz!-devices to monitor using the exporter.
|
| services.dendrite.settings.global.private_key | The path to the signing private key file, used to sign
requests and events.
nix-shell -p dendrite --command "generate-keys --private-key matrix_key.pem"
|
| services.matrix-synapse.settings.listeners.*.resources | List of HTTP resources to serve on this listener.
|
| services.homebridge.settings.accessories.*.name | Name of the accessory
|
| services.omnom.settings.app.disable_signup | Whether to enable restricting user creation.
|
| services.draupnir.settings.managementRoom | The room ID or alias where moderators can use the bot's functionality
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.bindPort | Port that the media proxy binds to.
|
| programs.openvpn3.log-service.settings | Options stored in /etc/openvpn3/log-service.json configuration file
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".url.host | Your instance's hostname for generating URLs throughout the app
|
| services.veilid.settings.core.capabilities.disable | A list of capabilities to disable (for example, DHTV to say you cannot store DHT information).
|
| services.grafana.settings.smtp.ehlo_identity | Name to be used as client identity for EHLO in SMTP dialog.
|
| services.postfix.settings.main.relay_domains | List of domains delivered via the relay transport.
https://www.postfix.org/postconf.5.html#relay_domains
|
| services.stash.settings.parallel_tasks | Number of parallel tasks to start during scan/generate
|
| services.lidarr.settings.update.automatically | Automatically download and install updates.
|
| services.radarr.settings.update.automatically | Automatically download and install updates.
|
| services.sonarr.settings.update.automatically | Automatically download and install updates.
|
| services.grafana.provision.alerting.rules.settings.apiVersion | Config file version.
|
| services.anubis.instances.<name>.settings.DIFFICULTY | The difficulty required for clients to solve the challenge
|
| services.angrr.settings.profile-policies.<name>.profile-paths | Paths to the Nix profile
|
| services.tor.settings.ServerTransportPlugin.transports | List of pluggable transports.
|
| hardware.tuxedo-drivers.settings.fn-lock | Enables or disables the laptop keyboard's Function (Fn) lock at boot
|
| services.radicle.ci.adapters.native.instances.<name>.settings.state | Directory where per-run directories are stored.
|
| services.your_spotify.settings.SPOTIFY_PUBLIC | The public client ID of your Spotify application
|
| services.armagetronad.servers.<name>.settings | Armagetron Advanced server rules configuration
|
| services.tuned.settings.sleep_interval | Interval in which the TuneD daemon is waken up and checks for events (in seconds).
|
| services.slskd.settings.retention.transfers.upload.errored | Lifespan of errored upload tasks.
|
| services.homebridge.settings.platforms.*.platform | Platform type
|
| services.nextcloud-spreed-signaling.settings.http.listen | IP and port to listen on for HTTP requests, in the format of ip:port
|
| services.taler.exchange.settings.exchange.CURRENCY_ROUND_UNIT | Smallest amount in this currency that can be transferred using the underlying RTGS
|
| services.veilid.settings.core.table_store.directory | The filesystem directory to store your table store within.
|
| services.veilid.settings.core.block_store.directory | The filesystem directory to store blocks for the block store.
|
| services.headscale.settings.dns.base_domain | Defines the base domain to create the hostnames for MagicDNS
|
| services.suricata.settings.app-layer.protocols.<name>.enabled | The option "enabled" takes 3 values - "yes", "no", "detection-only".
"yes" enables both detection and the parser, "no" disables both, and
"detection-only" enables protocol detection only (parser disabled).
|
| services.sourcehut.settings."builds.sr.ht".connection-string | SQLAlchemy connection string for the database.
|
| services.buffyboard.settings.input.touchscreen | Enable or disable the use of the touchscreen.
|
| services.warpgate.settings.postgres.certificate | Path to PostgreSQL listener certificate.
|
| services.postsrsd.settings.unprivileged-user | Unprivileged user to drop privileges to.
Our systemd unit never runs postsrsd as a privileged process, so this option is read-only.
|
| services.dependency-track.settings."alpine.oidc.teams.claim" | Defines the name of the claim that contains group memberships or role assignments in the provider's userinfo endpoint
|
| services.grafana.provision.alerting.rules.settings.deleteRules | List of alert rule UIDs that should be deleted.
|
| services.tuned.settings.reapply_sysctl | Whether to enable the reapplying of global sysctls after TuneD sysctls are applied.
|
| services.grafana.settings.security.secret_key | Secret key used for signing
|
| services.authelia.instances.<name>.settings.log.file_path | File path where the logs will be written
|
| services.epgstation.settings.concurrentEncodeNum | The maximum number of encoding jobs that EPGStation would run at the
same time.
|
| services.slskd.settings.directories.incomplete | Directory where incomplete downloading files are stored.
|
| services.borgmatic.settings.repositories.*.path | Path to the repository
|
| services.minidlna.settings.friendly_name | Name that the server presents to clients.
|
| services.sharkey.settings.fulltextSearch.provider | Which provider to use for full text search
|
| services.headscale.settings.oidc.extra_params | Custom query parameters to send with the Authorize Endpoint request.
|
| services.matrix-appservice-irc.settings.homeserver.url | The URL to the home server for client-server API calls
|
| services.consul-template.instances.<name>.settings.pid_file | Path to use for the pid file.
|
| services.mackerel-agent.settings.host_status.on_stop | Host status after agent shutdown.
|
| services.prometheus.exporters.process.settings.process_names | All settings expressed as an Nix attrset
|
| services.filesender.settings.admin_email | Email address of FileSender administrator(s)
|
| services.mobilizon.settings.":mobilizon".":instance".name | The fallback instance name if not configured into the admin UI
|
| services.syncthing.settings.folders.<name>.versioning.type | The type of versioning
|
| services.grafana.provision.alerting.muteTimings.settings | Grafana mute timings configuration in Nix
|
| services.dendrite.settings.sync_api.search.index_path | The path the search index will be created in.
|
| services.warpgate.settings.sso_providers | Configure OIDC single sign-on providers.
|
| services.anubis.instances.<name>.settings.WEBMASTER_EMAIL | If set, shows a contact email address when rendering error pages
|
| services.vmalert.instances.<name>.settings."datasource.url" | Datasource compatible with Prometheus HTTP API.
|
| services.kanidm.server.settings.online_backup.path | Path to the output directory for backups.
|
| services.nextcloud.settings.enabledPreviewProviders | The preview providers that should be explicitly enabled.
|
| services.libeufin.bank.settings.libeufin-bankdb-postgres.CONFIG | The database connection string for the libeufin-bank database.
|
| services.anubis.instances.<name>.settings.METRICS_BIND_NETWORK | The network family that the metrics server should bind to
|
| services.nextcloud-spreed-signaling.settings.grpc.targets | For target type static: List of GRPC targets to connect to for clustering mode.
|
| services.prometheus.exporters.fritz.settings.devices.*.name | Name to use for the device.
|
| services.warpgate.settings.ssh.external_port | The SSH listener is reachable via this port externally.
|
| services.grafana.settings.users.password_hint | Text used as placeholder text on login page for password input.
|
| services.grafana.provision.alerting.rules.settings.deleteRules.*.uid | Unique identifier for the rule
|
| services.nextcloud-spreed-signaling.settings.turn.servers | A list of TURN servers to use
|
| hardware.nvidia.datacenter.settings | Additional configuration options for fabricmanager.
|
| services.firewalld.settings.NftablesFlowtable | This may improve forwarded traffic throughput by enabling nftables flowtable
|
| services.grafana.settings.users.default_theme | Sets the default UI theme. system matches the user's system theme.
|
| services.grafana.provision.alerting.policies.settings | Grafana notification policies configuration in Nix
|
| services.postfix.settings.master.<name>.wakeupUnusedComponent | If set to false the component will only be woken
up if it is used
|
| services.sourcehut.settings."hg.sr.ht".changegroup-script | A changegroup script which is installed in every mercurial repo
|
| services.dependency-track.settings."alpine.oidc.teams.default" | Defines one or more team names that auto-provisioned OIDC users shall be added to
|
| services.dependency-track.settings."alpine.oidc.username.claim" | Defines the name of the claim that contains the username in the provider's userinfo endpoint
|
| services.grafana.settings.server.read_timeout | Sets the maximum time using a duration format (5s/5m/5ms)
before timing out read of an incoming request and closing idle connections.
0 means there is no timeout for reading the request.
|
| services.consul-template.instances.<name>.settings.template | Template section of consul-template
|
| services.borgmatic.settings.repositories.*.label | Label to the repository
|
| services.tor.settings.CookieAuthentication | See torrc manual.
|
| services.grafana.provision.alerting.rules.settings.deleteRules.*.orgId | Organization ID, default = 1
|
| services.syncthing.settings.options.localAnnounceEnabled | Whether to send announcements to the local LAN, also use such announcements to find other devices.
|
| services.sabnzbd.settings.servers.<name>.expire_date | If Notifications are enabled and an expiry date is
set, warn 5 days before expiry
|
| services.grafana.settings.database.ca_cert_path | The path to the CA certificate to use.
|
| services.readarr.settings.update.automatically | Automatically download and install updates.
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.publicUrl | URL under which the media proxy is publicly acccessible.
|
| services.angrr.settings.temporary-root-policies.<name>.filter.program | Path to the external filter program.
|
| services.warpgate.settings.http.external_port | The HTTP listener is reachable via this port externally.
|
| services.nextcloud-spreed-signaling.settings.turn.apikeyFile | The path to the file containing the value for turn.apikey
|
| services.nextcloud-spreed-signaling.settings.turn.secretFile | The path to the file containing the value for turn.secret
|
| services.your_spotify.settings.CLIENT_ENDPOINT | The endpoint of your web application
|
| services.immichframe.settings.Accounts.*.ImmichServerUrl | The URL of your Immich server.
|
| services.sabnzbd.settings.misc.bandwidth_max | Maximum bandwidth in bytes(!)/sec (supports prefixes)
|
| services.warpgate.settings.external_host | Configure the domain name of this Warpgate instance
|
| services.syncthing.settings.folders.<name>.versioning | How to keep changed/deleted files with Syncthing
|
| services.matrix-continuwuity.settings.global.port | The port(s) continuwuity will be running on
|
| services.synapse-auto-compressor.settings.levels | Sizes of each new level in the compression algorithm, as a comma-separated list
|
| services.journald.upload.settings.Upload.NetworkTimeoutSec | When network connectivity to the server is lost, this option
configures the time to wait for the connectivity to get restored
|
| services.suricata.settings.logging.stacktrace-on-signal | Requires libunwind to be available when Suricata is configured and built
|
| services.navidrome.settings.EnableInsightsCollector | Enable anonymous usage data collection, see https://www.navidrome.org/docs/getting-started/insights/ for details.
|
| services.your_spotify.settings.API_ENDPOINT | The endpoint of your server
This api has to be reachable from the device you use the website from not from the server
|
| services.dependency-track.settings."alpine.data.directory" | Defines the path to the data directory
|
| services.prometheus.exporters.script.settings.scripts.*.name | Name of the script.
|
| services.postfix.settings.main.mydestination | List of domain names intended for local delivery using /etc/passwd and /etc/aliases.
Do not include virtual domains in this list.
https://www.postfix.org/postconf.5.html#mydestination
|
| services.easytier.instances.<name>.settings.listeners | Listener addresses to accept connections from other peers
|
| services.waagent.settings.Provisioning.Enable | Whether to enable provisioning functionality in the agent
|
| services.grafana.provision.datasources.settings | Grafana datasource configuration in Nix
|
| services.warpgate.settings.sso_providers.*.name | Internal identifier of SSO provider.
|
| services.hercules-ci-agent.settings.staticSecretsDirectory | This is the default directory to look for statically configured secrets like cluster-join-token.key
|
| services.matrix-synapse.settings.listeners.*.resources.*.names | List of resources to host on this listener.
|
| services.prometheus.exporters.script.settings | Free-form configuration for script_exporter, expressed as a Nix attrset and rendered to YAML.
Migration note:
The previous format using script = "sleep 5" is no longer supported
|
| services.hddfancontrol.settings.<drive-bay-name>.extraArgs | Extra commandline arguments for hddfancontrol
|
| services.grafana.provision.alerting.rules.settings.groups.*.folder | Name of the folder the rule group will be stored in
|
| services.veilid.settings.client_api.ipc_enabled | veilid-server will respond to Python and other JSON client requests.
|
| services.grafana.provision.alerting.muteTimings.settings.muteTimes | List of mute time intervals to import or update.
|
| services.grafana-image-renderer.settings.rendering.mode | Rendering mode of grafana-image-renderer:
default: Creates on browser-instance
per rendering request.
reusable: One browser instance
will be started and reused for each rendering request.
clustered: allows to precisely
configure how many browser-instances are supposed to be used
|
| services.taler.exchange.settings.exchangedb-postgres.CONFIG | Database connection URI.
|
| services.taler.merchant.settings.merchantdb-postgres.CONFIG | Database connection URI.
|
| services.crowdsec-firewall-bouncer.settings.api_key | API key to authenticate with a local crowdsec API
|
| services.grafana.settings.users.allow_sign_up | Set to false to prohibit users from being able to sign up / create user accounts
|
| services.mackerel-agent.settings.host_status.on_start | Host status after agent startup.
|
| services.suricata.settings.exception-policy | Define a common behavior for all exception policies
|
| services.mpd.settings.bind_to_address | The address for the daemon to listen on
|
| services.pid-fan-controller.settings.heatSources.*.wildcardPath | Path of the heat source's hwmon temp_input file
|
| services.warpgate.settings.mysql.external_port | The MySQL listener is reachable via this port externally.
|
| services.nvme-rs.settings.thresholds.wear_warning | Wear warning threshold (%)
|
| services.livekit.settings.rtc.port_range_end | End of UDP port range for WebRTC
|
| services.headscale.settings.tls_cert_path | Path to already created certificate.
|
| services.grafana.provision.dashboards.settings.apiVersion | Config file version.
|
| services.nvme-rs.settings.thresholds.temp_warning | Temperature warning threshold (°C)
|
| services.grafana.provision.alerting.contactPoints.settings | Grafana contact points configuration in Nix
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceExportCircuitID | See torrc manual.
|
| users.mysql.pam | Settings for pam_mysql
|
| services.anubis.defaultOptions.settings.OG_PASSTHROUGH | Whether to enable Open Graph tag passthrough
|
| services.headscale.settings.dns.extra_records | Extra DNS records to expose to clients.
|
| services.angrr.settings.temporary-root-policies.<name>.priority | Priority of this policy
|
| services.nextcloud-spreed-signaling.settings.https.listen | IP and port to listen on for HTTPS requests, in the format of ip:port
|
| services.listmonk.database.settings."privacy.exportable" | List of fields which can be exported through an automatic export request
|
| services.dependency-track.settings."alpine.database.username" | Specifies the username to use when authenticating to the database.
|
| services.chhoto-url.settings.hash_algorithm | The hash algorithm to use for passwords and API keys
|
| services.nextcloud.settings.mail_smtpport | This depends on mail_smtpmode
|
| services.dependency-track.settings."alpine.database.mode" | Defines the database mode of operation
|
| services.grafana.provision.alerting.templates.settings | Grafana templates configuration in Nix
|
| services.lldap.settings.ldap_user_email | Admin email.
|
| services.anubis.instances.<name>.settings.METRICS_BIND | The address Anubis' metrics server listens to
|
| services.libeufin.nexus.settings.libeufin-nexusdb-postgres.CONFIG | The database connection string for the libeufin-nexus database.
|
| services.nextcloud.settings.mail_smtpname | This depends on mail_smtpauth
|
| services.tor.settings.AuthoritativeDirectory | See torrc manual.
|
| services.prowlarr.settings.update.automatically | Automatically download and install updates.
|
| services.whisparr.settings.update.automatically | Automatically download and install updates.
|
| services.prometheus.alertmanager-ntfy.settings | Configuration of alertmanager-ntfy
|
| services.slskd.settings.retention.transfers.download.errored | Lifespan of errored download tasks.
|
| services.grafana.provision.datasources.settings.prune | When true, provisioned datasources from this file will be deleted
automatically when removed from
services.grafana.provision.datasources.settings.datasources.
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceAllowUnknownPorts | See torrc manual.
|
| services.automysqlbackup.settings | automysqlbackup configuration
|
| services.hddfancontrol.settings.<drive-bay-name>.disks | Drive(s) to get temperature from
Can also use command substitution to automatically grab all matching drives; such as all scsi (sas) drives
|
| services.prometheus.exporters.fritz.settings.log_level | Log level to use for the exporter.
|
| services.nextcloud.settings.mail_smtpauth | This depends on mail_smtpmode
|
| services.warpgate.settings.sso_providers.*.label | SSO provider name displayed on login page.
|
| services.headscale.settings.oidc.allowed_users | Users allowed to authenticate even if not in allowedDomains.
|
| services.opensearch.settings."plugins.security.disabled" | Whether to enable the security plugin,
plugins.security.ssl.transport.keystore_filepath or
plugins.security.ssl.transport.server.pemcert_filepath and
plugins.security.ssl.transport.client.pemcert_filepath
must be set for this plugin to be enabled.
|
| services.sourcehut.settings."lists.sr.ht::worker".reject-mimetypes | Comma-delimited list of Content-Types to reject
|
| services.autosuspend.settings.suspend_cmd | The command to execute in case the host shall be suspended
|
| services.nextcloud-spreed-signaling.settings.backend.timeout | Timeout in seconds for requests to the backend
|
| services.lasuite-docs.collaborationServer.settings | Configuration options of collaboration server
|
| services.prometheus.exporters.nginxlog.settings.consul | Consul integration options
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceDirGroupReadable | See torrc manual.
|
| services.tuned.settings.update_interval | Update interval for dynamic tuning (in seconds).
|
| services.lldap.settings.jwt_secret_file | Path to a file containing the JWT secret.
|
| services.sabnzbd.settings.misc.bandwidth_perc | Percentage of bandwidth_max that sabnzbd is allowed to use.
0 means no limit.
|
| services.grafana.provision.alerting.muteTimings.settings.apiVersion | Config file version.
|
| services.sabnzbd.settings.ntfosd.ntfosd_enable | Whether to enable NotifyOSD alerts
|
| services.public-inbox.settings.publicinbox.nntpserver | NNTP URLs to this public-inbox instance
|
| services.public-inbox.settings.publicinbox.pop3server | POP3 URLs to this public-inbox instance
|
| services.public-inbox.settings.publicinbox.imapserver | IMAP URLs to this public-inbox instance
|
| services.autosuspend.settings.wakeup_cmd | The command to execute for scheduling a wake up of the system
|
| services.tor.settings.V3AuthoritativeDirectory | See torrc manual.
|
| services.suricata.settings.dpdk.interfaces.*.interface | See upstream docs: docs/capture-hardware/dpdk and docs/configuration/suricata-yaml.html#data-plane-development-kit-dpdk.
|
| services.prometheus.alertmanager-ntfy.settings.http.addr | The address to listen on.
|
| services.slskd.settings.retention.transfers.upload.cancelled | Lifespan of cancelled upload tasks.
|
| services.slskd.settings.retention.transfers.upload.succeeded | Lifespan of succeeded upload tasks.
|
| services.headscale.settings.prefixes.allocation | Strategy used for allocation of IPs to nodes, available options:
- sequential (default): assigns the next free IP from the previous given IP.
- random: assigns the next free IP from a pseudo-random IP generator (crypto/rand).
|
| services.quickwit.settings.listen_address | Listen address of Quickwit.
|
| services.grafana.provision.alerting.muteTimings.settings.muteTimes.*.name | Name of the mute time interval, must be unique
|
| services.openssh.settings.AuthorizedPrincipalsFile | Specifies a file that lists principal names that are accepted for certificate authentication
|
| services.postfix-tlspol.settings.server.socket-permissions | Permissions to the UNIX socket, if configured.
Due to hardening on the systemd unit the socket can never be created world readable/writable.
|
| services.headscale.settings.dns.extra_records.*.type | DNS record type.
|
| services.headscale.settings.dns.extra_records.*.name | DNS record name.
|
| services.nextcloud-spreed-signaling.settings.etcd.endpoints | List of static etcd endpoints to connect to.
|
| services.lasuite-docs.collaborationServer.settings.PORT | Port used by collaboration server to listen to
|
| services.anubis.instances.<name>.settings.OG_PASSTHROUGH | Whether to enable Open Graph tag passthrough
|
| services.biboumi.settings.xmpp_server_ip | The IP address to connect to the XMPP server on
|
| services.grafana.provision.alerting.policies.settings.apiVersion | Config file version.
|
| services.system76-scheduler.settings.cfsProfiles.default.latency | sched_latency_ns.
|
| services.nipap.settings.auth.default_backend | Name of auth backend to use by default.
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.signingKeyPath | Path to the signing key file for authenticated media.
|
| services.matrix-appservice-irc.settings.homeserver.domain | The 'domain' part for user IDs on this home server
|
| services.opentelemetry-collector.settings | Specify the configuration for Opentelemetry Collector in Nix
|
| services.matrix-appservice-irc.settings.ircService.mediaProxy.ttlSeconds | Lifetime in seconds, that generated URLs stay valid
|
| services.system76-scheduler.settings.cfsProfiles.default.preempt | Preemption mode.
|
| services.public-inbox.settings.publicinbox.wwwlisting | Controls which lists (if any) are listed for when the root
public-inbox URL is accessed over HTTP.
|
| services.prometheus.exporters.script.settings.scripts.*.script | Shell script to execute when metrics are requested.
|
| services.system76-scheduler.settings.cfsProfiles.default.nr-latency | sched_nr_latency.
|
| services.matrix-continuwuity.settings.global.address | Addresses (IPv4 or IPv6) to listen on for connections by the reverse proxy/tls terminator
|
| services.kerberos_server.settings.module | Modules to obtain Kerberos configuration from.
|
| services.kerberos_server.settings.realms | The realm(s) to serve keys for.
|
| services.crowdsec.settings.console.configuration | Attributes inside the console.yaml file.
|
| services.warpgate.settings.http.cookie_max_age | How long until logged in cookie expires.
|
| security.pam.u2f.settings.interactive | Set to prompt a message and wait before testing the presence of a U2F device
|
| services.pgbouncer.settings.pgbouncer.listen_port | Which port to listen on
|
| services.pgbouncer.settings.pgbouncer.pool_mode | Specifies when a server connection can be reused by other clients.
session
Server is released back to pool after client disconnects
|
| services.authelia.instances.<name>.settings.log.keep_stdout | Whether to also log to stdout when a file_path is defined.
|
| services.minidlna.settings.root_container | Use a different container as the root of the directory tree presented to clients.
|
| services.grafana.settings.database.max_open_conn | The maximum number of open connections to the database.
|
| services.grafana.provision.alerting.rules.settings.groups.*.interval | Interval that the rule group should be evaluated at
|
| services.tlsrpt.reportd.settings.sender_address | Sender address used for reports.
|
| services.grafana.settings.security.cookie_secure | Set to true if you host Grafana behind HTTPS.
|
| services.grafana.settings.database.max_idle_conn | The maximum number of connections in the idle connection pool.
|
| services.chhoto-url.settings.redirect_method | The redirect method to use.
|
| services.radicle.ci.adapters.native.instances.<name>.settings.base_url | Base URL for build logs (mandatory for access from CI broker page).
|
| services.grafana.provision.alerting.muteTimings.settings.deleteMuteTimes | List of mute time intervals that should be deleted.
|
| services.grafana.provision.datasources.settings.apiVersion | Config file version.
|
| services.headscale.settings.dns.extra_records.*.value | DNS record value (IP address).
|
| services.suricata.settings.classification-file | Suricata classification configuration file.
|
| services.parsedmarc.settings.elasticsearch.ssl | Whether to use an encrypted SSL/TLS connection.
|
| documentation.man.mandoc.settings | Configuration for man.conf(5)
|
| services.mobilizon.settings.":mobilizon".":instance".hostname | Your instance's hostname
|
| security.pam.u2f.settings.authfile | By default pam-u2f module reads the keys from
$XDG_CONFIG_HOME/Yubico/u2f_keys (or
$HOME/.config/Yubico/u2f_keys if XDG variable is
not set)
|
| services.hddfancontrol.settings.<drive-bay-name>.pwmPaths | PWM filepath(s) to control fan speed (under /sys), followed by initial and fan-stop PWM values
Can also use command substitution to ensure the correct hwmonX is selected on every boot
|
| services.transmission.settings.incomplete-dir | When enabled with
services.transmission.home
services.transmission.settings.incomplete-dir-enabled,
new torrents will download the files to this directory
|
| services.gitea.settings.service.DISABLE_REGISTRATION | By default any user can create an account on this gitea instance
|
| services.wgautomesh.settings.lan_discovery | Enable discovery of peers on the same LAN using UDP broadcast.
|
| services.system76-scheduler.settings.processScheduler.enable | Tweak scheduling of individual processes in real time.
|
| services.nextcloud-spreed-signaling.settings.backend.allowall | Allow any hostname as backend endpoint
|
| services.grafana.provision.alerting.contactPoints.settings.apiVersion | Config file version.
|
| services.transmission.settings.script-torrent-done-enabled | Whether to run
services.transmission.settings.script-torrent-done-filename
at torrent completion.
|
| services.nvme-rs.settings.thresholds.wear_critical | Wear critical threshold (%)
|
| services.grafana.provision.alerting.policies.settings.policies | List of contact points to import or update.
|
| services.prometheus.exporters.script.settings.scripts.*.timeout | Optional timeout for the script in seconds.
|
| services.archisteamfarm.settings | The ASF.json file, all the options are documented here
|
| services.parsedmarc.settings.elasticsearch.user | Username to use when connecting to Elasticsearch, if
required.
|
| services.matrix-synapse.settings.enable_metrics | Enable collection and rendering of performance metrics
|
| services.mpd.settings.music_directory | The directory or URI where MPD reads music from
|
| services.nvme-rs.settings.thresholds.temp_critical | Temperature critical threshold (°C)
|
| services.nvme-rs.settings.thresholds.spare_warning | Available spare warning threshold (%)
|
| services.matrix-synapse.settings.listeners.*.x_forwarded | Use the X-Forwarded-For (XFF) header as the client IP and not the
actual client IP.
|
| services.grafana.provision.dashboards.settings.providers | List of dashboards to insert/update.
|
| services.kanidm.server.settings.online_backup.schedule | The schedule for backups in cron format.
|
| services.grafana.settings.database.query_retries | This setting applies to sqlite3 only and controls the number of times the system retries a query when the database is locked.
|
| services.maubot.settings.crypto_database | Separate database URL for the crypto database
|
| services.angrr.settings.temporary-root-policies.<name>.filter.arguments | Extra command-line arguments pass to the external filter program.
|
| services.kerberos_server.settings.include | Files to include in the Kerberos configuration.
|
| services.grafana.provision.alerting.muteTimings.settings.deleteMuteTimes.*.orgId | Organization ID, default = 1.
|
| services.veilid.settings.core.network.dht.min_peer_count | Minimum number of nodes to keep in the peer table.
|
| services.grafana.provision.alerting.templates.settings.apiVersion | Config file version.
|
| services.mchprs.settings.block_in_hitbox | Allow placing blocks inside of players
(hitbox logic is simplified)
|
| services.transmission.settings.incomplete-dir-enabled | |
| services.grafana.settings.server.enforce_domain | Redirect to correct domain if the host header does not match the domain
|
| services.prometheus.exporters.fritz.settings.devices.*.username | Username to authenticate with the target device.
|
| services.prometheus.exporters.fritz.settings.devices.*.hostname | Hostname under which the target device is reachable.
|
| services.headscale.settings.dns.search_domains | Search domains to inject to Tailscale clients.
|
| services.factorio.mods-dat | Mods settings can be changed by specifying a dat file, in the mod
settings file
format.
|
| services.matrix-synapse.settings.public_baseurl | The public-facing base URL for the client API (not including _matrix/...)
|
| services.umurmur.settings.default_channel | The channel in which users will appear in when connecting.
|
| services.journald.upload.settings.Upload.ServerCertificateFile | SSL CA certificate in PEM format
|
| services.transmission.settings.script-torrent-done-filename | Executable to be run at torrent completion.
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceMaxStreamsCloseCircuit | See torrc manual.
|
| services.bonsaid.settings.*.delay_duration | Nanoseconds to wait after the previous state change before performing this transition
|
| services.kerberos_server.settings.realms.<name>.acl | The privileges granted to a user.
|
| services.geoipupdate.settings.DatabaseDirectory | The directory to store the database files in
|
| services.nextcloud.settings.mail_smtphost | This depends on mail_smtpmode
|
| services.transmission.settings.trash-original-torrent-files | Whether to delete torrents added from the
services.transmission.settings.watch-dir.
|
| services.tor.settings.UseMicrodescriptors | See torrc manual.
|
| services.syncthing.settings.options.maxFolderConcurrency | This option controls how many folders may concurrently be in I/O-intensive operations such as syncing or scanning
|
| services.parsedmarc.settings.elasticsearch.hosts | A list of Elasticsearch hosts to push parsed reports
to.
|
| services.warpgate.settings.postgres.external_port | The PostgreSQL listener is reachable via this port externally.
|
| services.grafana.settings.server.router_logging | Set to true for Grafana to log all HTTP requests (not just errors)
|
| virtualisation.cri-o.settings | Configuration for cri-o, see
https://github.com/cri-o/cri-o/blob/master/docs/crio.conf.5.md.
|
| services.syncthing.settings.folders.<name>.copyOwnershipFromParent | On Unix systems, tries to copy file/folder ownership from the parent directory (the directory it’s located in)
|
| services.mediagoblin.settings.mediagoblin.plugins | Plugins to enable
|
| services.firewalld.settings.IPv6_rpfilter | Performs reverse path filtering (RPF) on IPv6 packets as per RFC 3704
|
| services.slskd.settings.retention.transfers.download.cancelled | Lifespan of cancelled download tasks.
|
| services.slskd.settings.retention.transfers.download.succeeded | Lifespan of succeeded download tasks.
|
| services.grafana.provision.alerting.muteTimings.settings.deleteMuteTimes.*.name | Name of the mute time interval, must be unique
|
| services.firezone.server.settingsSecret.TOKENS_SALT | A file containing a unique base64 encoded secret for the
TOKENS_SALT
|
| services.reposilite.settings.compressionStrategy | Compression algorithm used by this instance of Reposilite.
none reduces usage of CPU & memory, but requires transfering more data.
|
| services.listmonk.database.settings."app.notify_emails" | Administrator emails for system notifications
|
| services.kanidm.server.settings.online_backup.versions | Number of backups to keep
|
| programs.openvpn3.log-service.settings.journald | Use systemd-journald
|
| services.veilid.settings.core.network.routing_table.node_id | Base64-encoded public key for the node, used as the node's ID.
|
| services.journald.upload.settings.Upload.TrustedCertificateFile | SSL CA certificate
|
| services.easytier.instances.<name>.settings.network_name | EasyTier network name.
|
| services.warpgate.settings.sso_providers.*.provider | SSO provider configurations.
|
| services.grafana.provision.dashboards.settings.providers.*.type | Dashboard provider type.
|
| services.grafana.provision.dashboards.settings.providers.*.name | A unique provider name.
|
| services.matrix-conduit.settings.global.database_path | Path to the conduit database, the directory where conduit will save its data
|
| services.homebridge.settings.accessories.*.accessory | Accessory type
|
| services.authelia.instances.<name>.settings.telemetry.metrics.enabled | Enable Metrics.
|
| services.journald.remote.settings.Remote.ServerCertificateFile | A path to a SSL certificate file in PEM format
|
| services.hercules-ci-agent.settings.concurrentTasks | Number of tasks to perform simultaneously
|
| services.omnom.settings.app.results_per_page | Number of results per page.
|
| services.borgmatic.settings.repositories | A required list of local or remote repositories with paths and
optional labels (which can be used with the --repository flag to
select a repository)
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.baseurl | The base URL of the ntfy.sh instance.
|
| services.stash.settings.preview_segments | Number of segments in a preview file
|
| services.stash.settings.sound_on_preview | Enable sound on mouseover previews
|
| services.grafana.provision.alerting.policies.settings.resetPolicies | List of orgIds that should be reset to the default policy.
|
| services.nextcloud.settings.mail_smtpdebug | Enable SMTP class debugging.
loglevel will likely need to be adjusted too.
See docs.
|
| services.firefox-syncserver.settings.tokenserver.enabled | Whether to enable the token service as well.
|
| services.veilid.settings.client_api.ipc_directory | IPC directory where file sockets are stored.
|
| services.taler.merchant.settings.merchant.LEGAL_PRESERVATION | How long to keep data in the database for tax audits after the transaction has completed.
|
| services.keycloak.settings.hostname-backchannel-dynamic | Enables dynamic resolving of backchannel URLs,
including hostname, scheme, port and context path
|
| services.auto-epp.settings.Settings.epp_state_for_AC | energy_performance_preference when on plugged in
See available epp states by running:
cat /sys/devices/system/cpu/cpu0/cpufreq/energy_performance_available_preferences
|
| services.mollysocket.settings.allowed_uuids | UUIDs of Signal accounts that may use this server
|
| services.synapse-auto-compressor.settings.chunk_size | The number of state groups to work on at once
|
| services.hddfancontrol.settings.<drive-bay-name>.logVerbosity | Verbosity of the log level
|
| services.firezone.server.settingsSecret.TOKENS_KEY_BASE | A file containing a unique base64 encoded secret for the
TOKENS_KEY_BASE
|
| services.firezone.server.settingsSecret.SECRET_KEY_BASE | A file containing a unique base64 encoded secret for the
SECRET_KEY_BASE
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".http.port | The port to run the server
|
| services.auto-epp.settings.Settings.epp_state_for_BAT | energy_performance_preference when on battery
See available epp states by running:
cat /sys/devices/system/cpu/cpu0/cpufreq/energy_performance_available_preferences
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".http.ip | The IP address to listen on
|
| services.glitchtip.settings.ENABLE_USER_REGISTRATION | When true, any user will be able to register
|
| nix.settings.trusted-substituters | List of binary cache URLs that non-root users can use (in
addition to those specified using
nix.settings.substituters) by passing
--option binary-caches to Nix commands.
|
| services.pgbouncer.settings.pgbouncer.listen_addr | Specifies a list (comma-separated) of addresses where to listen for TCP connections
|
| services.kanidm.server.settings.ldapbindaddress | Address and port the LDAP server is bound to
|
| services.authelia.instances.<name>.settings.telemetry.metrics.address | The address to listen on for metrics
|
| services.warpgate.settings.http.session_max_age | How long until a logged in session expires.
|
| services.grafana.provision.alerting.contactPoints.settings.contactPoints | List of contact points to import or update.
|
| services.syncthing.settings.folders.<name>.ignorePatterns | Syncthing can be configured to ignore certain files in a folder using ignore patterns
|
| services.prometheus.alertmanagerIrcRelay.settings | Configuration for Alertmanager IRC Relay as a Nix attribute set
|
| services.warpgate.settings.config_provider | Source of truth of users
|
| services.matrix-appservice-irc.settings.database.connectionString | The database connection string
|
| services.sabnzbd.settings.misc.inet_exposure | Restrictions for access from non-local IP addresses
|
| services.kea.dhcp-ddns.configFile | Kea DHCP-DDNS configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/ddns.html
|
| services.matrix-synapse.settings.listeners.*.resources.*.compress | Whether synapse should compress HTTP responses to clients that support it
|
| services.openssh.settings.PasswordAuthentication | Specifies whether password authentication is allowed.
|
| services.livekit.settings.rtc.use_external_ip | When set to true, attempts to discover the host's public IP via STUN
|
| services.system76-scheduler.settings.cfsProfiles.default.bandwidth-size | sched_cfs_bandwidth_slice_us.
|
| services.tlsrpt.reportd.settings.sendmail_script | Path to a sendmail-compatible executable for delivery reports.
|
| services.slskd.settings.flags.force_share_scan | Force a rescan of shares on every startup.
|
| services.chhoto-url.settings.disable_frontend | Whether to disable the frontend.
|
| virtualisation.podman.defaultNetwork.settings | Settings for podman's default network.
|
| services.parsedmarc.settings.general.save_forensic | Save forensic report data to Elasticsearch and/or Splunk.
|
| services.grafana.provision.alerting.templates.settings.templates | List of templates to import or update.
|
| services.nezha-agent.settings.skip_procs_count | Do not monitor the number of processes.
|
| services.prometheus.exporters.fritz.settings.devices.*.host_info | Enable extended host info for this device. Warning: This will heavily increase scrape time.
|
| services.matrix-synapse.settings.max_upload_size | The largest allowed upload size in bytes
|
| programs.openvpn3.log-service.settings.log_level | How verbose should the logging be
|
| services.grafana.provision.alerting.contactPoints.settings.contactPoints.*.name | Name of the contact point
|
| services.chhoto-url.settings.try_longer_slugs | Whether to try a longer UID upon collision.
|
| services.nextcloud-spreed-signaling.settings.sessions.hashkeyFile | The path to the file containing the value for sessions.hashkey
|
| services.filebeat.settings.output.elasticsearch.hosts | The list of Elasticsearch nodes to connect to
|
| services.journald.remote.settings.Remote.TrustedCertificateFile | A path to a SSL CA certificate file in PEM format, or all
|
| services.simplesamlphp.<name>.settings.baseurlpath | URL where SimpleSAMLphp can be reached.
|
| services.mobilizon.settings.":mobilizon".":instance".email_from | The email for the From: header in emails
|
| services.system76-scheduler.settings.cfsProfiles.responsive.latency | sched_latency_ns.
|
| programs.openvpn3.log-service.settings.timestamp | Add timestamp log file
|
| services.kerberos_server.settings.realms.<name>.acl.*.target | The principals that 'access' applies to.
|
| services.livekit.settings.rtc.port_range_start | Start of UDP port range for WebRTC
|
| services.system76-scheduler.settings.cfsProfiles.responsive.preempt | Preemption mode.
|
| services.system76-scheduler.settings.cfsProfiles.responsive.nr-latency | sched_nr_latency.
|
| services.nextcloud.settings.mail_smtpmode | Which mode to use for sending mail
|
| services.prometheus.exporters.nginxlog.settings.namespaces | Namespaces to collect the metrics for
|
| services.easytier.instances.<name>.settings.instance_name | Identify different instances on same host
|
| networking.networkmanager.settings | Configuration added to the generated NetworkManager.conf, note that you can overwrite settings with this
|
| services.openldap.configDir | Use this config directory instead of generating one from the
settings option
|
| services.nextcloud-spreed-signaling.settings.https.certificate | Path to the certificate used for the HTTPS listener
|
| services.matrix-continuwuity.settings.global.server_name | The server_name is the name of this server
|
| virtualisation.xen.store.settings | The OCaml-based Xen Store Daemon configuration
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.mode | The file access mode to use when creating this file or directory.
|
| services.nextcloud.settings.trusted_proxies | Trusted proxies, to provide if the nextcloud installation is being
proxied to secure against e.g. spoofing.
|
| services.nextcloud.settings.trusted_domains | Trusted domains, from which the nextcloud installation will be
accessible
|
| services.kea.ctrl-agent.configFile | Kea Control Agent configuration as a path, see https://kea.readthedocs.io/en/kea-3.0.2/arm/agent.html
|
| services.veilid.settings.core.network.routing_table.bootstrap | Host name of existing well-known Veilid bootstrap servers for the network to connect to.
|
| services.grafana.provision.alerting.templates.settings.templates.*.name | Name of the template, must be unique
|
| services.grafana.provision.alerting.contactPoints.settings.deleteContactPoints | List of receivers that should be deleted.
|
| services.mediagoblin.settings.mediagoblin.sql_engine | Database to use.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".database | Name of the database
|
| services.nextcloud-spreed-signaling.settings.sessions.blockkeyFile | The path to the file containing the value for sessions.blockkey
|
| services.maubot.settings.plugin_databases.sqlite | The directory where SQLite plugin databases should be stored.
|
| services.swapspace.settings.lower_freelimit | Lower free-space threshold: if the percentage of free space drops below this number, additional swapspace is allocated
|
| services.firezone.server.settingsSecret.RELEASE_COOKIE | A file containing a unique secret identifier for the Erlang
cluster
|
| virtualisation.xen.store.settings.pidFile | Path to the Xen Store Daemon PID file.
|
| services.system76-scheduler.settings.processScheduler.useExecsnoop | Use execsnoop (otherwise poll the precess list periodically).
|
| services.glitchtip.settings.ENABLE_ORGANIZATION_CREATION | When false, only superusers will be able to create new organizations after the first
|
| services.nextcloud-spreed-signaling.settings.stats.allowed_ips | List of IP addresses that are allowed to access the debug, stats and metrics endpoints
|
| services.adguardhome.settings.schema_version | Schema version for the configuration
|
| services.headscale.settings.oidc.allowed_domains | Allowed principal domains. if an authenticated user's domain
is not in this list authentication request will be rejected.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".username | User used to connect to the database
|
| services.postfix.settings.main.mynetworks_style | The method used for generating the default value for mynetworks, if that option is unset.
https://www.postfix.org/postconf.5.html#mynetworks_style
|
| services.swapspace.settings.upper_freelimit | Upper free-space threshold: if the percentage of free space exceeds this number, swapspace will attempt to free up swapspace
|
| services.biboumi.settings.policy_directory | A directory that should contain the policy files,
used to customize Botan’s behaviour
when negotiating the TLS connections with the IRC servers.
|
| services.tuned.settings.recommend_command | Whether to enable recommend functionality.
|
| services.quickwit.settings.grpc_listen_port | The port to listen on for gRPC traffic.
|
| services.matrix-conduit.settings.global.trusted_servers | Servers trusted with signing server keys.
|
| services.grafana.settings.users.auto_assign_org | Set to true to automatically add new users to the main organization (id 1)
|
| services.grafana.settings.users.allow_org_create | Set to false to prohibit users from creating new organizations.
|
| services.snapserver.settings.tcp.bind_to_address | Address to listen on for snapclient connections.
|
| services.pixelfed.secretFile | A secret file to be sourced for the .env settings
|
| services.public-inbox.settings.publicinboxmda.spamcheck | If set to spamc, public-inbox-watch(1) will filter spam
using SpamAssassin.
|
| services.minidlna.settings.notify_interval | The interval between announces (in seconds)
|
| services.minidlna.settings.enable_subtitles | Enable subtitle support on unknown clients.
|
| services.maubot.settings.server.plugin_base_path | The base path for plugin endpoints
|
| services.warpgate.settings.http.sni_certificates | Certificates for additional domains.
|
| services.grafana.provision.alerting.contactPoints.settings.deleteContactPoints.*.uid | Unique identifier for the receiver
|
| services.grafana.provision.dashboards.settings.providers.*.options.path | Path grafana will watch for dashboards
|
| services.mbpfan.settings.general.polling_interval | The polling interval.
|
| services.grafana.settings.database.client_key_path | The path to the client key
|
| services.grafana.settings.security.admin_password | Default admin password
|
| services.grafana.provision.alerting.contactPoints.settings.deleteContactPoints.*.orgId | Organization ID, default = 1.
|
| services.grafana.provision.alerting.templates.settings.deleteTemplates | List of alert rule UIDs that should be deleted.
|
| services.firezone.server.settingsSecret.LIVE_VIEW_SIGNING_SALT | A file containing a unique base64 encoded secret for the
LIVE_VIEW_SIGNING_SALT
|
| services.kerberos_server.settings.includedir | Directories containing files to include in the Kerberos configuration.
|
| services.grafana.settings.server.static_root_path | Root path for static assets.
|
| services.snapserver.settings.http.bind_to_address | Address to listen on for snapclient connections.
|
| services.wordpress.sites.<name>.extraConfig | Any additional text to be appended to the wp-config.php
configuration file
|
| services.nextcloud.settings.mail_smtpsecure | This depends on mail_smtpmode
|
| services.parsedmarc.settings.general.save_aggregate | Save aggregate report data to Elasticsearch and/or Splunk.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.enable | Boost Pipewire client priorities.
|
| services.nvme-rs.settings.thresholds.error_threshold | Error count warning threshold
|
| services.grafana.settings.users.default_language | This setting configures the default UI language, which must be a supported IETF language tag, such as en-US.
|
| services.parsedmarc.settings.elasticsearch.password | The password to use when connecting to Elasticsearch,
if required
|
| services.veilid.settings.core.protected_store.directory | The filesystem directory to store your protected store in.
|
| services.system76-scheduler.settings.processScheduler.refreshInterval | Process list poll interval, in seconds
|
| services.warpgate.settings.http.sni_certificates.*.key | Path to private key.
|
| services.grafana.settings.users.viewers_can_edit | Viewers can access and use Explore and perform temporary edits on panels in dashboards they have access to
|
| services.grafana.provision.datasources.settings.datasources | List of datasources to insert/update.
|
| virtualisation.xen.store.settings.quota.maxSize | Size limit for transactions.
|
| services.radicale.config | Radicale configuration, this will set the service
configuration file
|
| services.firezone.server.settingsSecret.COOKIE_SIGNING_SALT | A file containing a unique base64 encoded secret for the
COOKIE_SIGNING_SALT
|
| services.parsedmarc.settings.elasticsearch.cert_path | The path to a TLS certificate bundle used to verify
the server's certificate.
|
| services.dovecot2.pluginSettings | Plugin settings for dovecot in general, e.g. sieve, sieve_default, etc
|
| virtualisation.xen.store.settings.quota.maxPath | Path limit for the quota system.
|
| services.grafana.provision.alerting.templates.settings.deleteTemplates.*.orgId | Organization ID, default = 1.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.age | Delete a file when it reaches a certain age
|
| services.matrix-synapse.settings.media_store_path | Directory where uploaded images and attachments are stored.
|
| services.matrix-synapse.settings.max_image_pixels | Maximum number of pixels that will be thumbnailed
|
| services.matrix-synapse.settings.signing_key_path | Path to the signing key to sign messages with.
|
| services.grafana.settings.database.isolation_level | Only the MySQL driver supports isolation levels in Grafana
|
| services.grafana.provision.datasources.settings.datasources.*.url | Url of the datasource.
|
| services.ergochat.configFile | Path to configuration file
|
| services.matrix-appservice-irc.settings.ircService.passwordEncryptionKeyPath | Location of the key with which IRC passwords are encrypted
for storage
|
| services.tor.settings.VersioningAuthoritativeDirectory | See torrc manual.
|
| services.grafana.provision.alerting.templates.settings.deleteTemplates.*.name | Name of the template, must be unique
|
| services.swapspace.settings.cache_elasticity | Percentage of cache space considered to be "free"
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.nice | Niceness.
|
| services.headscale.settings.derp.update_frequency | Frequency to update DERP maps.
|
| services.headscale.settings.database.postgres.password_file | A file containing the password corresponding to
database.user.
|
| services.matrix-synapse.settings.listeners.*.bind_addresses | IP addresses to bind the listener to.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.user | The user of the file
|
| documentation.man.mandoc.settings.output.style | Path to the file used for an external style-sheet
|
| services.tor.relay.onionServices.<name>.settings.HiddenServiceNumIntroductionPoints | See torrc manual.
|
| services.healthchecks.settings.REGISTRATION_OPEN | A boolean that controls whether site visitors can create new accounts
|
| services.grafana.provision.datasources.settings.datasources.*.name | Name of the datasource
|
| services.grafana.provision.datasources.settings.datasources.*.type | Datasource type
|
| services.btrbk.instances.<name>.settings.stream_compress | Compress the btrfs send stream before transferring it from/to remote locations using a
compression command.
|
| services.snapserver.settings.stream.bind_to_address | Address to listen on for snapclient connections.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.prio | CPU scheduler priority.
|
| services.system76-scheduler.settings.cfsProfiles.responsive.bandwidth-size | sched_cfs_bandwidth_slice_us.
|
| services.postgresql.settings.log_line_prefix | A printf-style string that is output at the beginning of each log line
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.ioPrio | IO scheduler priority.
|
| services.hickory-dns.configFile | Path to an existing toml file to configure hickory-dns with
|
| virtualisation.xen.store.settings.quota.maxWatch | Maximum number of watches by the Xenstore Watchdog.
|
| services.discourse.siteSettings | Discourse site settings
|
| documentation.man.mandoc.settings.output.toc | Whether to enable printing a table of contents near the beginning of the HTML output
of mandoc(1) if an input file contains at least two
non-standard sections
.
|
| services.kerberos_server.settings.realms.<name>.acl.*.access | The changes the principal is allowed to make.
The "all" permission does not imply the "get-keys" permission
|
| services.easytier.instances.<name>.settings.network_secret | EasyTier network credential used for verification and
encryption
|
| services.kerberos_server.settings.realms.<name>.acl.*.principal | Which principal the rule applies to
|
| services.maubot.settings.plugin_databases.postgres | The connection URL for plugin database
|
| virtualisation.xen.store.settings.quota.enable | Whether to enable the quota system.
|
| services.grafana.provision.datasources.settings.datasources.*.uid | Custom UID which can be used to reference this datasource in other parts of the configuration, if not specified will be generated automatically.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.class | CPU scheduler class.
|
| services.hickory-dns.settings.listen_addrs_ipv4 | List of ipv4 addresses on which to listen for DNS queries.
|
| services.hickory-dns.settings.listen_addrs_ipv6 | List of ipv6 addresses on which to listen for DNS queries.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.group | The group of the file
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.type | The type of operation to perform on the file
|
| services.nextcloud-spreed-signaling.settings.backend.backendtype | Type of backend configuration
|
| services.system76-scheduler.settings.cfsProfiles.default.wakeup-granularity | sched_wakeup_granularity_ns.
|
| services.grafana.provision.alerting.templates.settings.templates.*.template | Alerting with a custom text template
|
| services.grafana.provision.datasources.settings.datasources.*.jsonData | Extra data for datasource plugins.
|
| virtualisation.xen.store.settings.perms.enable | Whether to enable the node permission system.
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.ioClass | IO scheduler class.
|
| services.matrix-conduit.settings.global.allow_federation | Whether this server federates with other servers.
|
| services.matrix-tuwunel.settings.global.allow_federation | Whether this server federates with other servers.
|
| virtualisation.docker.daemon.settings | Configuration for docker daemon
|
| services.dependency-track.settings."alpine.oidc.user.provisioning" | Specifies if mapped OpenID Connect accounts are automatically created upon successful
authentication
|
| services.matrix-tuwunel.settings.global.trusted_servers | Servers listed here will be used to gather public keys of other servers
(notary trusted key servers)
|
| services.headscale.settings.noise.private_key_path | Path to noise private key file, generated automatically if it does not exist.
|
| virtualisation.xen.store.settings.quota.maxEntity | Entity limit for transactions.
|
| virtualisation.xen.store.settings.enableMerge | Whether to enable transaction merge support.
|
| services.nextcloud.settings.mail_smtptimeout | This depends on mail_smtpmode
|
| services.grafana.settings.security.allow_embedding | When false, the HTTP header X-Frame-Options: deny will be set in Grafana HTTP responses
which will instruct browsers to not allow rendering Grafana in a <frame>, <iframe>, <embed> or <object>
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.mode | The file access mode to use when creating this file or directory.
|
| services.filesender.settings.log_facilities | Defines where FileSender logging is sent
|
| services.grafana.provision.datasources.settings.deleteDatasources | List of datasources that should be deleted from the database.
|
| services.grafana.settings.database.client_cert_path | The path to the client cert
|
| services.livekit.ingress.settings.rtc_config.port_range_end | End of UDP port range for WebRTC
|
| services.grafana.settings.security.disable_gravatar | Set to true to disable the use of Gravatar for user profile images.
|
| services.matrix-conduit.settings.global.max_request_size | Max request size in bytes
|
| services.matrix-tuwunel.settings.global.max_request_size | Max request size in bytes
|
| services.snapserver.settings.tcp-control.bind_to_address | Address to listen on for snapclient connections.
|
| services.openssh.settings.KbdInteractiveAuthentication | Specifies whether keyboard-interactive authentication is allowed.
|
| services.biboumi.settings.realname_from_jid | Whether the realname and username of each biboumi
user will be extracted from their JID
|
| services.tlsrpt.reportd.settings.organization_name | Name of the organization sending out the reports.
|
| services.omnom.settings.smtp.connection_timeout | Connection timeout duration in seconds.
|
| security.agnos.settings.accounts.*.certificates | Certificates for agnos to issue or renew.
|
| services.matrix-conduit.settings.global.database_backend | The database backend for the service
|
| services.sftpgo.settings.httpd.bindings.*.enable_web_admin | Enable the built-in web admin for this interface binding.
|
| services.nipap.settings.auth.auth_cache_timeout | Seconds to store cached auth entries for.
|
| hardware.tuxedo-drivers.settings.charging-profile | The maximum charge level to help reduce battery wear:
high_capacity charges to 100% (driver default)
balanced charges to 90%
stationary charges to 80% (maximum lifespan)
Note: Regardless of the configured charging profile, the operating system will always report the battery as being charged to 100%.
|
| services.nvme-rs.settings.email.smtp_password_file | File containing SMTP password
|
| services.matrix-tuwunel.settings.global.allow_encryption | Whether new encrypted rooms can be created
|
| services.matrix-conduit.settings.global.allow_encryption | Whether new encrypted rooms can be created
|
| services.omnom.settings.smtp.tls_allow_insecure | Whether to enable Whether to allow insecure TLS..
|
| services.grafana.provision.datasources.settings.datasources.*.access | Access mode. proxy or direct (Server or Browser in the UI)
|
| services.grafana.settings.database.server_cert_name | The common name field of the certificate used by the mysql or postgres server
|
| services.grafana.provision.datasources.settings.deleteDatasources.*.orgId | Organization ID of the datasource to delete.
|
| services.headscale.settings.derp.server.private_key_path | Path to derp private key file, generated automatically if it does not exist.
|
| services.grafana.provision.datasources.settings.deleteDatasources.*.name | Name of the datasource to delete.
|
| hardware.tuxedo-drivers.settings.charging-priority | These options manage the trade-off between battery charging and CPU performance when the USB-C power supply cannot provide sufficient power for both simultaneously:
charge_battery prioritizes battery charging (driver default)
performance prioritizes maximum CPU performance
|
| services.maubot.settings.plugin_directories | Plugin directory paths
|
| services.searx.limiterSettings | Limiter settings for SearXNG.
|
| services.maubot.configMutable | Whether maubot should write updated config into extraConfigFile. This will make your Nix module settings have no effect besides the initial config, as extraConfigFile takes precedence over NixOS settings!
|
| services.matrix-continuwuity.settings.global.database_path | Path to the continuwuity database, the directory where continuwuity will save its data
|
| services.grafana.settings.security.cookie_samesite | Sets the SameSite cookie attribute and prevents the browser from sending this cookie along with cross-site requests
|
| services.swapspace.settings.buffer_elasticity | Percentage of buffer space considered to be "free"
|
| services.undervolt.useTimer | Whether to set a timer that applies the undervolt settings every 30s
|
| services.headscale.settings.database.sqlite.write_ahead_log | Enable WAL mode for SQLite
|
| services.mpd.settings.playlist_directory | The directory where MPD stores playlists
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.age | Delete a file when it reaches a certain age
|
| services.maubot.settings.plugin_directories.load | The directories from which plugins should be loaded
|
| services.nezha-agent.settings.disable_send_query | Disable sending TCP/ICMP/HTTP requests.
|
| services.public-inbox.settings.publicinboxwatch.watchspam | If set, mail in this maildir will be trained as spam and
deleted from all watched inboxes
|
| services.system76-scheduler.settings.processScheduler.pipewireBoost.profile.matchers | Process matchers.
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.user | The user of the file
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.tags | Tags to add to ntfy.sh messages
|
| services.public-inbox.settings.publicinboxwatch.spamcheck | If set to spamc, public-inbox-watch(1) will filter spam
using SpamAssassin.
|
| services.grafana.provision.datasources.settings.datasources.*.editable | Allow users to edit datasources from the UI.
|
| services.postfix.settings.main.message_size_limit | Maximum size of an email message in bytes.
https://www.postfix.org/postconf.5.html#message_size_limit
|
| virtualisation.xen.store.settings.quota.maxWatchEvents | Maximum number of outstanding watch events per watch.
|
| services.nextcloud.settings.mail_from_address | FROM address that overrides the built-in sharing-noreply and lostpassword-noreply FROM addresses
|
| services.matrix-tuwunel.settings.global.unix_socket_path | Listen on a UNIX socket at the specified path
|
| users.mysql.nss | Settings for libnss-mysql
|
| services.maubot.settings.plugin_directories.upload | The directory where uploaded new plugins should be stored.
|
| documentation.man.mandoc.settings.output.width | The ASCII and UTF-8 output width, default is 78
|
| services.prometheus.exporters.fritz.settings.devices.*.password_file | Path to a file which contains the password to authenticate with the target device
|
| services.snapserver.settings.tcp-streaming.bind_to_address | Address to listen on for snapclient connections.
|
| services.mediagoblin.settings.mediagoblin.email_debug_mode | Disable email debug mode to start sending outgoing mails
|
| services.snipe-it.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.maubot.settings.plugin_directories.trash | The directory where old plugin versions and conflicting plugins should be moved
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.enable | Boost foreground process priorities.
(And de-boost background ones)
|
| services.matrix-tuwunel.settings.global.unix_socket_perms | The default permissions (in octal) to create the UNIX socket with.
|
| services.grafana.settings.security.x_xss_protection | Set to true to enable the X-XSS-Protection header,
which tells browsers to stop pages from loading when they detect reflected cross-site scripting (XSS) attacks.
Note: this is the default in Grafana, it's turned off here
since it's recommended to not use this header anymore.
|
| services.etebase-server.settings.allowed_hosts.allowed_host1 | The main host that is allowed access.
|
| services.nextcloud.settings.skeletondirectory | The directory where the skeleton files are located
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.tags.*.tag | The tag to add
|
| virtualisation.containerd.settings | Verbatim lines to add to containerd.toml
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.type | The type of operation to perform on the file
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.group | The group of the file
|
| services.nvme-rs.settings.check_interval_secs | Check interval in seconds
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Storage.Repo".socket_dir | Path to the postgres socket directory
|
| virtualisation.xen.store.settings.quota.maxRequests | Maximum number of requests per transaction.
|
| services.firezone.server.settingsSecret.COOKIE_ENCRYPTION_SALT | A file containing a unique base64 encoded secret for the
COOKIE_ENCRYPTION_SALT
|
| services.warpgate.settings.ssh.inactivity_timeout | How long can user be inactive until Warpgate terminates the connection.
|
| documentation.man.mandoc.settings.output.man | A template for linked manuals (usually via the Xr macro) in HTML
output
|
| services.sftpgo.settings.httpd.bindings.*.enable_web_client | Enable the built-in web client for this interface binding.
|
| services.system76-scheduler.settings.cfsProfiles.responsive.wakeup-granularity | sched_wakeup_granularity_ns.
|
| systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.argument | An argument whose meaning depends on the type of operation
|
| services.warpgate.settings.ssh.keepalive_interval | If nothing is received from the client for this amount of time, server will send a keepalive message.
|
| services.nextcloud.settings.mail_sendmailmode | For smtp, the sendmail binary is started with the parameter -bs: Use the SMTP protocol on standard input and output
|
| services.dendrite.settings.mscs.database.connection_string | Database for exerimental MSC's.
|
| services.stash.settings.gallery_cover_regex | Regex used to identify images as gallery covers
|
| services.stash.settings.preview_exclude_end | Duration of start of video to exclude when generating previews
|
| services.searx.faviconsSettings | Favicons settings for SearXNG.
|
| documentation.man.mandoc.settings.manpath | Override the default search path for man(1),
apropos(1), and makewhatis(8)
|
| virtualisation.xen.store.settings.xenstored.log.file | Path to the Xen Store log file.
|
| services.listmonk.database.settings."privacy.domain_blocklist" | E-mail addresses with these domains are disallowed from subscribing.
|
| services.livekit.ingress.settings.rtc_config.use_external_ip | When set to true, attempts to discover the host's public IP via STUN
|
| services.libeufin.bank.settings.libeufin-bank.SUGGESTED_WITHDRAWAL_EXCHANGE | Exchange that is suggested to wallets when withdrawing
|
| services.grafana.settings.database.conn_max_lifetime | Sets the maximum amount of time a connection may be reused
|
| services.mobilizon.settings.":mobilizon".":instance".email_reply_to | The email for the Reply-To: header in emails
|
| services.nextcloud.settings.overwriteprotocol | Force Nextcloud to always use HTTP or HTTPS i.e. for link generation
|
| services.grafana.settings.users.auto_assign_org_id | Set this value to automatically add new users to the provided org
|
| services.mollysocket.settings.allowed_endpoints | List of UnifiedPush servers
|
| virtualisation.xen.store.settings.xenstored.log.level | Logging level for the Xen Store.
|
| services.grafana.provision.datasources.settings.datasources.*.secureJsonData | Datasource specific secure configuration
|
| services.xray.enable | Whether to run xray server
|
| virtualisation.xen.store.settings.ringScanInterval | Perodic scanning for all the rings as a safenet for lazy clients
|
| services.stash.settings.sequential_scanning | Modifies behaviour of the scanning functionality to generate support files (previews/sprites/phash) at the same time as fingerprinting/screenshotting
|
| virtualisation.xen.store.settings.persistent | Whether to activate the filed base backend.
|
| documentation.man.mandoc.settings.output.includes | A string of relative path used as a template for the output path of
linked header files (usually via the In macro) in HTML output
|
| services.matrix-synapse.settings.turn_shared_secret | The shared secret used to compute passwords for the TURN server
|
| virtualisation.docker.daemon.settings.live-restore | Allow dockerd to be restarted without affecting running container
|
| security.agnos.settings.accounts.*.certificates.*.domains | Domains the certificate represents
|
| services.headscale.settings.oidc.strip_email_domain | Whether the domain part of the email address should be removed when generating namespaces.
|
| services.livekit.ingress.settings.rtc_config.port_range_start | Start of UDP port range for WebRTC
|
| documentation.man.mandoc.settings.output.indent | Number of blank characters at the left margin for normal text,
default of 5 for mdoc(7) and 7 for
man(7)
|
| services.monica.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.nice | Niceness.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.nice | Niceness.
|
| services.doh-server.settings.ecs_use_precise_ip | If ECS is added to the request, let the full IP address or cap it to 24 or 128 mask
|
| services.crab-hole.settings.blocklist.include_subdomains | Whether to enable Include subdomains.
|
| virtualisation.docker.rootless.daemon.settings | Configuration for docker daemon
|
| services.headscale.settings.oidc.client_secret_path | Path to OpenID Connect client secret file
|
| services.cgit.<name>.repos | cgit repository settings, see cgitrc(5)
|
| services.borgmatic.settings.source_directories | List of source directories and files to backup
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.prio | CPU scheduler priority.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.prio | CPU scheduler priority.
|
| services.nextcloud-spreed-signaling.settings.clients.internalsecretFile | The path to the file containing the value for clients.internalsecret
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.ioPrio | IO scheduler priority.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.ioPrio | IO scheduler priority.
|
| nix.checkAllErrors | If enabled, checks the nix.conf parsing for any kind of error
|
| services.matrix-conduit.settings.global.allow_registration | Whether new users can register on this server.
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.topic | Note: when using ntfy.sh and other public instances
it is recommended to set this option to an empty string and set the actual topic via
services.prometheus.alertmanager-ntfy.extraConfigFiles since
the topic in ntfy.sh is essentially a password
|
| documentation.man.mandoc.settings.output.fragment | Whether to omit the declaration and the , , and
elements and only emit the subtree below the element in HTML
output of mandoc(1)
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.class | CPU scheduler class.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.class | CPU scheduler class.
|
| services.warpgate.settings.http.sni_certificates.*.certificate | Path to certificate.
|
| documentation.man.mandoc.settings.output.paper | This option is for generating PostScript and PDF output
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.ioClass | IO scheduler class.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.ioClass | IO scheduler class.
|
| services.minio.configDir | The config directory, for the access keys and other settings.
|
| services.grafana.settings.analytics.reporting_enabled | When enabled Grafana will send anonymous usage statistics to stats.grafana.org
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.priority | The ntfy.sh message priority (see https://docs.ntfy.sh/publish/#message-priority for more information)
|
| virtualisation.containers.storage.settings | storage.conf configuration
|
| services.postfix.settings.main.recipient_delimiter | Set of characters used as the delimiters for address extensions
|
| services.acme-dns.settings.api.disable_registration | Whether to disable the HTTP registration endpoint.
|
| services.lldap.settings.ldap_user_pass_file | Path to a file containing the default admin password
|
| security.agnos.settings.dns_listen_addr | Address for agnos to listen on
|
| boot.initrd.systemd.tmpfiles.settings.<config-name>.<path>.<tmpfiles-type>.argument | An argument whose meaning depends on the type of operation
|
| security.auditd.settings.space_left | If the free space in the filesystem containing log_file drops below this value, the audit daemon takes the action specified by
space_left_action
|
| virtualisation.xen.store.settings.xenstored.accessLog.file | Path to the Xen Store access log file.
|
| services.matrix-synapse.settings.dynamic_thumbnails | Whether to generate new thumbnails on the fly to precisely match
the resolution requested by the client
|
| services.dendrite.settings.sync_api.database.connection_string | Database for the Sync API.
|
| services.matrix-continuwuity.settings.global.allow_federation | Whether this server federates with other servers.
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.templates.title | The ntfy.sh message title template.
|
| services.matrix-continuwuity.settings.global.trusted_servers | Servers listed here will be used to gather public keys of other servers
(notary trusted key servers)
|
| services.matrix-synapse.settings.enable_registration | Enable registration for new users.
|
| services.zitadel.extraSettingsPaths | A list of paths to extra settings files
|
| services.pgbouncer.settings.pgbouncer.default_pool_size | How many server connections to allow per user/database pair
|
| services.dependency-track.settings."alpine.oidc.team.synchronization" | This option will ensure that team memberships for OpenID Connect users are dynamic and
synchronized with membership of OpenID Connect groups or assigned roles
|
| services.matrix-synapse.settings.trusted_key_servers | The trusted servers to download signing keys from.
|
| services.grafana.settings.analytics.check_for_updates | When set to false, disables checking for new versions of Grafana from Grafana's GitHub repository
|
| services.matrix-continuwuity.settings.global.max_request_size | Max request size in bytes
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.tags.*.condition | The condition under which this tag should be added
|
| services.maubot.settings.plugin_databases.postgres_opts | Overrides for the default database_opts when using a non-default postgres connection URL.
|
| services.matrix-tuwunel.settings.global.allow_registration | Whether new users can register on this server
|
| services.movim.secretFile | The secret file to be sourced for the .env settings.
|
| services.chhoto-url.settings.cache_control_header | The Cache-Control header to send.
|
| services.buffyboard.configFile | Path to an INI format configuration file to provide Buffyboard
|
| services.headscale.settings.derp.auto_update_enabled | Whether to automatically update DERP maps on a set frequency.
|
| services.matrix-continuwuity.settings.global.allow_encryption | Whether new encrypted rooms can be created
|
| services.lasuite-docs.collaborationServer.settings.COLLABORATION_SERVER_ORIGIN | Origins allowed to connect to the collaboration server
|
| services.lasuite-docs.collaborationServer.settings.COLLABORATION_BACKEND_BASE_URL | URL to the backend server base
|
| services.dendrite.settings.media_api.database.connection_string | Database for the Media API.
|
| services.dendrite.settings.relay_api.database.connection_string | Database for the Relay Server.
|
| virtualisation.xen.store.settings.quota.transaction | Maximum number of transactions.
|
| virtualisation.xen.store.settings.perms.enableWatch | Whether to enable the watch permission system
|
| services.matrix-synapse.settings.url_preview_enabled | Is the preview URL API enabled? If enabled, you must specify an
explicit url_preview_ip_range_blacklist of IPs that the spider is
denied from accessing.
|
| services.pgbouncer.settings.pgbouncer.max_client_conn | Maximum number of client connections allowed
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.background.matchers | Process matchers.
|
| services.system76-scheduler.settings.processScheduler.foregroundBoost.foreground.matchers | Process matchers.
|
| services.peertube.settings.video_transcription.enabled | Enable automatic transcription of videos.
|
| services.grafana.settings.plugins.preinstall_disabled | When set to true, disables the Background Plugin Installer, which runs before Grafana starts
|
| services.matrix-synapse.settings.macaroon_secret_key | Secret key for authentication tokens
|
| services.grafana.settings.users.verify_email_enabled | Require email validation before sign up completes.
|
| services.grafana.settings.database.transaction_retries | This setting applies to sqlite3 only and controls the number of times the system retries a transaction when the database is locked.
|
| services.nextcloud.settings.mail_template_class | Replaces the default mail template layout
|
| virtualisation.xen.store.settings.quota.maxOutstanding | Maximum outstanding requests, i.e. in-flight requests / domain.
|
| services.grafana.settings.server.serve_from_sub_path | Serve Grafana from subpath specified in the root_url setting
|
| services.cross-seed.useGenConfigDefaults | Whether to use the option defaults from the configuration generated by
cross-seed gen-config
|
| services.grafana.settings.users.auto_assign_org_role | The role new users will be assigned for the main organization (if the auto_assign_org setting is set to true).
|
| services.dendrite.settings.key_server.database.connection_string | Database for the Key Server (for end-to-end encryption).
|
| services.matrix-continuwuity.settings.global.unix_socket_perms | The default permissions (in octal) to create the UNIX socket with.
|
| services.authelia.instances.<name>.settings.default_2fa_method | Default 2FA method for new users and fallback for preferred but disabled methods.
|
| services.stash.settings.notifications_enabled | If we should send notifications to the desktop
|
| services.cloud-init.config | raw cloud-init configuration
|
| services.quorum.genesis | Blockchain genesis settings.
|
| services.stash.settings.preview_exclude_start | Duration of end of video to exclude when generating previews
|
| services.cgit.<name>.gitHttpBackend.enable | Whether to bypass cgit and use git-http-backend for HTTP clones
|
| services.szurubooru.server.settings.delete_source_files | Whether to delete thumbnails and source files on post delete.
|
| services.synapse-auto-compressor.settings.chunks_to_compress | chunks_to_compress chunks of size chunk_size will be compressed
|
| services.gatus.configFile | Path to the Gatus configuration file
|
| services.dendrite.settings.room_server.database.connection_string | Database for the Room Server.
|
| virtualisation.xen.store.settings.conflict.burstLimit | Limits applied to domains whose writes cause other domains' transaction
commits to fail
|
| services.buffyboard.settings.quirks.fbdev_force_refresh | If true and using the framebuffer backend, this triggers a display refresh after every draw operation
|
| services.matrix-synapse.settings.tls_private_key_path | PEM encoded private key for TLS
|
| services.nezha-agent.settings.skip_connection_count | Do not monitor the number of connections.
|
| services.chhoto-url.settings.allow_capital_letters | Whether to allow capital letters in slugs.
|
| services.kmscon.useXkbConfig | Whether to configure keymap from xserver keyboard settings.
|
| services.matrix-continuwuity.settings.global.unix_socket_path | Listen on a UNIX socket at the specified path
|
| services.invidious.extraSettingsFile | A file including Invidious settings
|
| services.nezha-agent.settings.use_ipv6_country_code | Use ipv6 countrycode to report location.
|
| security.pam.rssh.settings.auth_key_file | Path to file with trusted public keys in OpenSSH's authorized_keys format
|
| services.litellm.settings.environment_variables | Environment variables to pass to the Lite
|
| services.xonotic.settings.sv_termsofservice_url | URL for the Terms of Service for playing on your server.
|
| services.jellyfin.forceEncodingConfig | Whether to overwrite Jellyfin's encoding.xml configuration file on each service start
|
| services.grafana.settings.security.csrf_trusted_origins | List of additional allowed URLs to pass by the CSRF check
|
| services.scrutiny.settings.web.influxdb.tls.insecure_skip_verify | Whether to enable skipping TLS verification when connecting to InfluxDB.
|
| virtualisation.containers.containersConf.settings | containers.conf configuration
|
| services.h2o.hosts | The hosts config to be merged with the settings
|
| services.nsd.zones | Define your zones here
|
| services.dependency-track.database.type | h2 database is not recommended for a production setup.
postgresql this settings it recommended for production setups.
manual the module doesn't handle database settings.
|
| services.jitsi-meet.config | Client-side web application settings that override the defaults in config.js
|
| services.doh-server.settings.log_guessed_client_ip | Enable log IP from HTTPS-reverse proxy header: X-Forwarded-For or X-Real-IP
Note: http uri/useragent log cannot be controlled by this config
|
| services.matrix-synapse.settings.tls_certificate_path | PEM encoded X509 certificate for TLS
|
| services.fediwall.nginx | Allows customizing the nginx virtualHost settings
|
| services.nextcloud.settings.default_phone_region | An ISO 3166-1
country code which replaces automatic phone-number detection
without a country code
|
| services.postfix.settings.main.smtpd_tls_chain_files | List of paths to the server private keys and certificates.
The order of items matters and a private key must always be followed by the corresponding certificate.
https://www.postfix.org/postconf.5.html#smtpd_tls_chain_files
|
| services.warpgate.settings.ssh.host_key_verification | Specify host key verification action when connecting to a SSH target with unknown/differing host key.
|
| console.useXkbConfig | If set, configure the virtual console keymap from the xserver
keyboard settings.
|
| services.tt-rss.auth.autoLogin | Automatically login user on remote or other kind of externally supplied
authentication, otherwise redirect to login form as normal
|
| virtualisation.xen.store.settings.conflict.maxHistorySeconds | Limits applied to domains whose writes cause other domains' transaction
commits to fail
|
| services.prometheus.alertmanager-ntfy.settings.ntfy.notification.templates.description | The ntfy.sh message description template.
|
| services.agorakit.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.librenms.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.peertube.settings.video_transcription.engine_path | Custom engine path for local transcription.
|
| services.stash.settings.write_image_thumbnails | Write image thumbnails to disk when generating on the fly
|
| services.nextcloud-spreed-signaling.settings.backend.connectionsperhost | Maximum number of concurrent backend connections per host
|
| services.slskd.settings.remote_file_management | Whether to enable modification of share contents through the web ui.
|
| programs.openvpn3.netcfg.settings.systemd_resolved | Whether to use systemd-resolved integration
|
| services.artalk.allowModify | allow Artalk store the settings to config file persistently
|
| services.matrix-continuwuity.settings.global.allow_registration | Whether new users can register on this server
|
| services.biboumi.settings.persistent_by_default | Whether all rooms will be persistent by default:
the value of the “persistent” option in the global configuration of each
user will be “true”, but the value of each individual room will still
default to false
|
| services.pgbouncer.settings.pgbouncer.max_db_connections | Do not allow more than this many server connections per database (regardless of user)
|
| services.jupyter.user | Name of the user used to run the jupyter service
|
| services.matrix-synapse.settings.trusted_key_servers.*.server_name | Hostname of the trusted server.
|
| services.mobilizon.settings.":mobilizon"."Mobilizon.Web.Endpoint".has_reverse_proxy | Whether you use a reverse proxy
|
| services.maubot.settings.server.override_resource_path | Override path from where to load UI resources.
|
| services.bluemap.maps | Settings for files in maps/
|
| services.mediagoblin.settings.mediagoblin.allow_registration | Whether to enable user self registration
|
| services.tuned.ppdSettings | Settings for TuneD's power-profiles-daemon compatibility service.
|
| services.rmfakecloud.extraSettings | Extra settings in the form of a set of key-value pairs
|
| security.auditd.settings.admin_space_left | This is a numeric value in mebibytes (MiB) that tells the audit daemon when to perform a configurable action because the system is running
low on disk space
|
| services.biboumi.settings.realname_customization | Whether the users will be able to use
the ad-hoc commands that lets them configure
their realname and username.
|
| programs.openvpn3.log-service.settings.log_dbus_details | Add D-Bus details in log file/syslog
|
| services.doh-server.configFile | The config file for the doh-server
|
| services.dendrite.settings.federation_api.database.connection_string | Database for the Federation API.
|
| services.veilid.settings.core.network.detect_address_changes | Should veilid-core detect and notify on network address changes?
|
| services.movim.h2o.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.opendkim.keyPath | The path that opendkim should put its generated private keys into
|
| services.crab-hole.configFile | The config file of crab-hole
|
| services.cgit.<name>.gitHttpBackend.checkExportOkFiles | Whether git-http-backend should only export repositories that contain a git-daemon-export-ok file
|
| programs.rush.global | The global statement defines global settings.
|
| services.anuko-time-tracker.nginx | With this option, you can customize the Nginx virtualHost settings.
|
| services.sabnzbd.configFile | Path to config file (deprecated, use settings instead and set this value to null)
|
| services.sourcehut.settings."hg.sr.ht".clone_bundle_threshold | .hg/store size (in MB) past which the nightly job generates clone bundles.
|
| services.coturn.realm | The default realm to be used for the users when no explicit
origin/realm relationship was found in the database, or if the TURN
server is not using any database (just the commands-line settings
and the userdb file)
|
| services.deepin.dde-daemon.enable | Whether to enable daemon for handling the deepin session settings.
|
| services.nextcloud.settings.mail_smtpstreamoptions | This depends on mail_smtpmode
|
| services.newt.blueprint | Blueprint for declarative settings, see Newt Blueprint docs for more information.
|
| services.nezha-agent.settings.disable_command_execute | Disable executing the command from dashboard.
|
| services.headscale.settings.tls_letsencrypt_listen | When HTTP-01 challenge is chosen, letsencrypt must set up a
verification endpoint, and it will be listening on:
:http = port 80.
|
| services.dendrite.settings.app_service_api.database.connection_string | Database for the Appservice API.
|
| services.dendrite.settings.user_api.device_database.connection_string | Database for the User API, devices.
|
| services.dendrite.settings.client_api.registration_disabled | Whether to disable user registration to the server
without the shared secret.
|
| services.h2o.hosts.<name>.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.bookstack.nginx | With this option, you can customize the nginx virtualHost settings.
|
| services.timekpr.adminUsers | All listed users will become part of the timekpr group so they can manage timekpr settings without requiring sudo.
|
| services.longview.apiKey | Longview API key
|
| services.grafana.settings.analytics.feedback_links_enabled | Set to false to remove all feedback links from the UI.
|
| services.geoclue2.appConfig | Specify extra settings per application.
|
| security.agnos.settings.accounts.*.private_key_path | Path of the PEM-encoded private key for this account
|
| services.grav.systemSettings | Settings written to user/config/system.yaml.
|
| services.postfix.settings.main.smtp_tls_security_level | The client TLS security level.
Use dane with a local DNSSEC validating DNS resolver enabled.
https://www.postfix.org/postconf.5.html#smtp_tls_security_level
|
| services.akkoma.config | Configuration for Akkoma
|
| services.dolibarr.h2o.tls.recommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.xandikos.nginx.enable | Configure the nginx reverse proxy settings.
|
| services.mediagoblin.settings.mediagoblin.email_sender_address | Email address which notices are sent from.
|
| services.longview.apiKeyFile | A file containing the Longview API key
|
| services.grafana.settings.security.x_content_type_options | Set to false to disable the X-Content-Type-Options response header
|
| services.h2o.defaultTLSRecommendations | By default, H2O, without prejudice, will use as many TLS versions &
cipher suites as it & the TLS library (OpenSSL) can support
|
| services.dendrite.settings.user_api.account_database.connection_string | Database for the User API, accounts.
|
| services.stash.settings.preview_segment_duration | Preview segment duration, in seconds
|
| services.factorio.saveName | The name of the savegame that will be used by the server
|
| services.bonsaid.configFile | Path to a .json file specifying the state transitions
|
| services.pgbouncer.settings.pgbouncer.max_user_connections | Do not allow more than this many server connections per user (regardless of database)
|
| services.mailman.webSettings | Overrides for the default mailman-web Django settings.
|
| services.graphite.web.extraConfig | Graphite webapp settings
|
| virtualisation.xen.store.settings.conflict.rateLimitIsAggregate | If the conflict.rateLimitIsAggregate option is true, then after each
tick one point of conflict-credit is given to just one domain: the
one at the front of the queue
|
| services.chhoto-url.settings.custom_landing_directory | The path of a directory which contains a custom landing page.
|
| services.matrix-synapse.log | Default configuration for the loggers used by matrix-synapse and its workers
|
| services.neo4j.extraServerConfig | Extra configuration for Neo4j Community server
|
| services.chhoto-url.settings.public_mode_expiry_delay | The maximum expiry delay in seconds to force in public mode.
|
| services.cyrus-imap.cyrusSettings | Cyrus configuration settings
|
| services.cyrus-imap.imapdSettings | IMAP configuration settings
|
| services.grafana.settings.security.csrf_additional_headers | List of allowed headers to be set by the user
|
| services.kanidm.unix.settings.kanidm.pam_allowed_login_groups | Kanidm groups that are allowed to login using PAM.
|
| services.matrix-conduit.settings.global.allow_check_for_updates | Whether to allow Conduit to automatically contact
https://conduit.rs hourly to check for important Conduit news
|
| services.postfix.settings.main.smtpd_tls_security_level | The server TLS security level
|
| services.cpupower-gui.enable | Enables dbus/systemd service needed by cpupower-gui
|
| services.grafana.settings.security.content_security_policy | Set to true to add the Content-Security-Policy header to your requests
|
| services.journald.rateLimitBurst | Configures the rate limiting burst limit (number of messages per
interval) that is applied to all messages generated on the system
|
| services.filesender.settings.storage_filesystem_path | When using storage type filesystem this is the absolute path to the file system where uploaded files are stored until they expire
|
| services.doh-server.settings.ecs_allow_non_global_ip | By default, non global IP addresses are never forwarded to upstream servers
|
| services.davis.database.urlFile | A file containing the database connection url
|
| services.bluemap.coreSettings | Settings for the core.conf file, see upstream docs.
|
| services.trilium-server.nginx.enable | Configure the nginx reverse proxy settings.
|
| services.matrix-synapse.settings.app_service_config_files | A list of application service config file to use
|
| services.sitespeed-io.runs | A list of run configurations
|
| services.hardware.lcd.server.usbGroup | The group to use for settings permissions
|
| services.headscale.settings.tls_letsencrypt_hostname | Domain name to request a TLS certificate for.
|
| services.tuned.settings.default_instance_priority | Default instance (unit) priority.
|
| services.radicale.rights | Configuration for Radicale's rights file
|
| services.cloudlog.extraConfig | Any additional text to be appended to the config.php
configuration file
|
| services.bitlbee.extraSettings | Will be inserted in the Settings section of the config file.
|
| security.agnos.settings.accounts.*.certificates.*.key_output_file | Output path for the certificate private key
|
| services.hardware.bolt.enable | Whether to enable Bolt, a userspace daemon to enable
security levels for Thunderbolt 3 on GNU/Linux
|
| services.nomad.extraSettingsPaths | Additional settings paths used to configure nomad
|
| services.freshrss.api.enable | Whether to enable API access for mobile apps and third-party clients (Google Reader API and Fever API)
|
| programs.clash-verge.tunMode | Whether to enable Setcap for TUN Mode
|
| services.nextcloud.settings.mail_send_plaintext_only | Email will be sent by default with an HTML and a plain text body
|
| services.postgresql.settings.shared_preload_libraries | List of libraries to be preloaded.
|
| services.minetest-server.config | Settings to add to the minetest config file
|
| services.syncthing.configDir | The path where the settings and keys will exist.
|
| services.kanidm.serverSettings | Settings for Kanidm, see
the documentation
and example configuration
for possible values.
|
| services.snipe-it.config | Snipe-IT configuration options to set in the
.env file
|
| services.warpgate.settings.http.trust_x_forwarded_headers | Trust X-Forwarded-* headers
|
| services.matrix-synapse.settings.url_preview_url_blacklist | Optional list of URL matches that the URL preview spider is
denied from accessing.
|
| services.portunus.seedSettings | Seed settings for users and groups
|
| services.bluemap.webappSettings | Settings for the webapp.conf file, see upstream docs.
|
| services.buffyboard.settings.quirks.ignore_unused_terminals | If true, buffyboard won't automatically update the layout of a new terminal and
draw the keyboard, if the terminal is not opened by any process
|
| services.logstash.extraSettings | Extra Logstash settings in YAML format.
|
| services.grafana.settings.analytics.check_for_plugin_updates | When set to false, disables checking for new versions of installed plugins from https://grafana.com
|
| services.mediawiki.extraConfig | Any additional text to be appended to MediaWiki's
LocalSettings.php configuration file
|
| services.apcupsd.configText | Contents of the runtime configuration file, apcupsd.conf
|
| services.github-runners.<name>.user | User under which to run the service
|
| services.mattermost.environmentFile | Environment file (see systemd.exec(5)
"EnvironmentFile=" section for the syntax) which sets config options
for mattermost (see the Mattermost documentation)
|
| services.btrbk.extraPackages | Extra packages for btrbk, like compression utilities for stream_compress.
Note: This option will get deprecated in future releases
|
| services.grafana.settings.security.strict_transport_security | Set to true if you want to enable HTTP Strict-Transport-Security (HSTS) response header
|
| services.veilid.settings.core.protected_store.allow_insecure_fallback | If we can't use system-provided secure storage, should we proceed anyway?
|
| services.mailman.enablePostfix | Enable Postfix integration
|
| services.olivetin.extraConfigFiles | Config files to merge into the settings defined in services.olivetin.settings
|
| services.stash.settings.video_file_naming_algorithm | Hash algorithm to use for generated file naming
|
| services.matrix-synapse.settings.registration_shared_secret | If set, allows registration by anyone who also has the shared
secret, even if registration is otherwise disabled
|
| services.pfix-srsd.configurePostfix | Whether to configure the required settings to use pfix-srsd in the local Postfix instance.
|
| services.gitlab-runner.configFile | Configuration file for gitlab-runner.
configFile takes precedence over services.
checkInterval and concurrent will be ignored too
|
| services.monica.config | monica configuration options to set in the
.env file
|
| services.oink.domains | List of attribute sets containing configuration for each domain
|
| services.lldap.settings.force_ldap_user_pass_reset | Force reset of the admin password
|
| services.openldap.mutableConfig | Whether to allow writable on-line configuration
|
| services.filebeat.inputs | Inputs specify how Filebeat locates and processes input data
|
| services.tinc.networks.<name>.extraConfig | Extra lines to add to the tinc service configuration file
|
| services.wgautomesh.settings.upnp_forward_external_port | Public port number to try to redirect to this machine's Wireguard
daemon using UPnP IGD.
|
| services.yarr.environmentFile | Environment file for specifying additional settings such as secrets
|
| services.jitsi-meet.interfaceConfig | Client-side web-app interface settings that override the defaults in interface_config.js
|
| services.foundationdb.tls | FoundationDB Transport Security Layer (TLS) settings.
|
| services.schleuder.listDefaults | Default settings for lists (list-defaults.yml)
|
| services.libvirtd.autoSnapshot.vms | If specified only the list of VMs will be snapshotted else all existing one
|
| services.matrix-continuwuity.settings.global.allow_announcements_check | If enabled, continuwuity will send a simple GET request periodically to
https://continuwuity.org/.well-known/continuwuity/announcements for any new announcements made.
|
| services.flexget.systemScheduler | When true, execute the runs via the flexget-runner.timer
|
| services.pgbouncer.settings.pgbouncer.ignore_startup_parameters | By default, PgBouncer allows only parameters it can keep track of in startup packets:
client_encoding, datestyle, timezone and standard_conforming_strings
|
| services.multipath.overrides | This section defines values for attributes that should override the
device-specific settings for all devices.
|
| services.librespeed.secrets | Attribute set of filesystem paths
|
| services.grafana.settings.database.locking_attempt_timeout_sec | For mysql, if the migrationLocking feature toggle is set,
specify the time (in seconds) to wait before failing to lock the database for the migrations.
|
| services.yggdrasil.configFile | A file which contains JSON or HJSON configuration for yggdrasil
|
| fonts.fontconfig.localConf | System-wide customization file contents, has higher priority than
defaultFonts settings.
|
| services.factorio.extraSettingsFile | File, which is dynamically applied to server-settings.json before
startup
|
| services.prometheus.remoteWrite.*.sigv4 | Configures AWS Signature Version 4 settings.
|
| services.grafana.settings.security.data_source_proxy_whitelist | Define a whitelist of allowed IP addresses or domains, with ports,
to be used in data source URLs with the Grafana data source proxy
|
| services.postgresql.systemCallFilter | Configures the syscall filter for postgresql.service
|
| programs.starship.presets | Presets files to be merged with settings in order.
|
| boot.isNspawnContainer | Whether the machine is running in an nspawn container
|
| services.mattermost.preferNixConfig | If both mutableConfig and this option are set, the Nix configuration
will take precedence over any settings configured in the server
console.
|
| services.prosody.muc.*.tombstoneExpiry | This settings controls how long a tombstone is considered
valid
|
| services.stash.settings.create_image_clip_from_videos | Create Image Clips from Video extensions when Videos are disabled in Library
|
| services.asterisk.useTheseDefaultConfFiles | Sets these config files to the default content
|
| services.agorakit.config | Agorakit configuration options to set in the
.env file
|
| services.komodo-periphery.extraSettings | Extra settings to add to the generated TOML config.
|
| services.akkoma.initDb.enable | Whether to automatically initialise the database on startup
|
| services.packagekit.vendorSettings | Additional settings passed straight through to Vendor.conf
|
| services.bluemap.webserverSettings | Settings for the webserver.conf file, usually not required.
See upstream docs.
|
| services.postsrsd.configurePostfix | Whether to configure the required settings to use postsrsd in the local Postfix instance.
|
| services.bookstack.config | BookStack configuration options to set in the
.env file
|
| services.cryptpad.configureNginx | Configure Nginx as a reverse proxy for Cryptpad
|
| services.clamav.clamonacc.enable | Whether to enable ClamAV on-access scanner
|
| services.netbird.useRoutingFeatures | Enables settings required for NetBird's routing features: Network Resources, Network Routes & Exit Nodes
|
| services.rathole.credentialsFile | Path to a TOML file to be merged with the settings
|
| services.pufferpanel.environment | Environment variables to set for the service
|
| services.veilid.settings.core.protected_store.always_use_insecure_storage | Should we bypass any attempt to use system-provided secure storage?
|
| services.filebeat.modules | Filebeat modules provide a quick way to get started
processing common log formats
|
| services.postfix-tlspol.configurePostfix | Whether to configure the required settings to use postfix-tlspol in the local Postfix instance.
|
| services.nginx.recommendedTlsSettings | Enable recommended TLS settings.
|
| services.easytier.instances.<name>.configFile | Path to easytier config file
|
| services.foundationdb.locality | FoundationDB locality settings.
|
| services.grafana.settings.security.disable_initial_admin_creation | Disable creation of admin user on first start of Grafana.
|
| services.matrix-synapse.settings.url_preview_ip_range_blacklist | List of IP address CIDR ranges that the URL preview spider is denied
from accessing.
|
| services.dendrite.settings.global.trusted_third_party_id_servers | Lists of domains that the server will trust as identity
servers to verify third party identifiers such as phone
numbers and email addresses
|
| services.matrix-synapse.settings.url_preview_ip_range_whitelist | List of IP address CIDR ranges that the URL preview spider is allowed
to access even if they are specified in url_preview_ip_range_blacklist.
|
| services.headscale.settings.tls_letsencrypt_challenge_type | Type of ACME challenge to use, currently supported types:
HTTP-01 or TLS-ALPN-01.
|
| hardware.nvidia.nvidiaSettings | Whether to enable nvidia-settings, NVIDIA's GUI configuration tool
.
|
| services.metricbeat.modules | Metricbeat modules are responsible for reading metrics from the various sources
|
| services.privoxy.inspectHttps | Whether to configure Privoxy to inspect HTTPS requests, meaning all
encrypted traffic will be filtered as well
|
| security.agnos.settings.accounts.*.certificates.*.fullchain_output_file | Output path for the full chain including the acquired certificate
|
| services.librenms.environmentFile | File containing env-vars to be substituted into the final config
|
| services.sanoid.datasets.<name>.recursive | Whether to recursively snapshot dataset children
|
| services.printing.cups-pdf.instances.<name>.confFileText | This will contain the contents of cups-pdf.conf for this instance, derived from settings
|
| services.karakeep.extraEnvironment | Environment variables to pass to Karakaeep
|
| i18n.inputMethod.fcitx5.plasma6Support | Use qt6 versions of fcitx5 packages
|
| services.biboumi.credentialsFile | Path to a configuration file to be merged with the settings
|
| services.nginx.recommendedGzipSettings | Enable recommended gzip settings
|
| services.discourse.backendSettings | Additional settings to put in the
discourse.conf file
|
| services.sunshine.applications | Configuration for applications to be exposed to Moonlight
|
| services.stash.settings.show_one_time_moved_notification | Whether a small notification to inform the user that Stash will no longer show a terminal window, and instead will be available in the tray
|
| services.apache-kafka.configFiles.serverProperties | Kafka server.properties configuration file path
|
| programs.captive-browser.enable | Whether to enable captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings.
|
| services.nginx.recommendedZstdSettings | Enable recommended zstd settings
|
| services.nginx.recommendedUwsgiSettings | Whether to enable recommended uwsgi settings if a vhost does not specify the option manually.
|
| services.nginx.recommendedProxySettings | Whether to enable recommended proxy settings if a vhost does not specify the option manually.
|
| services.displayManager.dms-greeter.configFiles | List of DankMaterialShell configuration files to copy into the greeter
data directory at /var/lib/dms-greeter
|
| services.nextcloud.configureRedis | Whether to configure Nextcloud to use the recommended Redis settings for small instances.
The Nextcloud system check recommends to configure either Redis or Memcache for file lock caching.
The notify_push app requires Redis to be configured
|
| services.listmonk.database.mutableSettings | Database settings will be reset to the value set in this module if this is not enabled
|
| services.easytier.instances.<name>.extraSettings | Extra settings to add to easytier-‹name›.toml.
|
| hardware.cpu.amd.ryzen-smu.enable | Whether to enable ryzen_smu, a linux kernel driver that exposes access to the SMU (System Management Unit) for certain AMD Ryzen Processors
|
| services.crossfire-server.configFiles | Text to append to the corresponding configuration files
|
| services.mattermost.mutableConfig | Whether the Mattermost config.json is writeable by Mattermost
|
| services.xserver.displayManager.sx.enable | Whether to enable the "sx" pseudo-display manager, which allows users
to start manually via the "sx" command from a vt shell
|
| services.maubot.settings.plugin_databases.postgres_max_conns_per_plugin | Maximum number of connections per plugin instance.
|
| users.users.<name>.linger | Whether to enable or disable lingering for this user
|
| services.opencloud.environment | Extra environment variables to set for the service
|
| services.opencloud.environmentFile | An environment file as defined in systemd.exec(5)
|
| services.grafana.settings.users.user_invite_max_lifetime_duration | The duration in time a user invitation remains valid before expiring
|
| services.prometheus.remoteRead.*.tls_config | Configures the remote read request's TLS settings.
|
| services.nginx.recommendedBrotliSettings | Enable recommended brotli settings
|
| services.headscale.settings.ephemeral_node_inactivity_timeout | Time before an inactive ephemeral node is deleted.
|
| services.grafana.settings.security.strict_transport_security_preload | Set to true to enable HSTS preloading option
|
| environment.wvdial.pppDefaults | Default ppp settings for wvdial.
|
| services.yggdrasil.openMulticastPort | Whether to open the UDP port used for multicast peer discovery
|
| services.dovecot2.imapsieve.mailbox.*.name | This setting configures the name of a mailbox for which administrator scripts are configured
|
| services.prometheus.remoteWrite.*.tls_config | Configures the remote write request's TLS settings.
|
| services.weblate.configurePostgresql | Whether to enable and configure a local PostgreSQL server by creating a user and database for weblate
|
| services.easytier.instances.<name>.configServer | Configure the instance from config server
|
| programs.chromium.initialPrefs | Initial preferences are used to configure the browser for the first run
|
| services.nginx.experimentalZstdSettings | Enable alpha quality zstd module with recommended settings
|
| services.stash.settings.dangerous_allow_public_without_auth | Learn more at https://docs.stashapp.cc/networking/authentication-required-when-accessing-stash-from-the-internet/
|
| services.mastodon.configureNginx | Configure nginx as a reverse proxy for mastodon
|
| services.tailscale.useRoutingFeatures | Enables settings required for Tailscale's routing features like subnet routers and exit nodes
|
| services.firezone.server.provision.accounts | All accounts to provision
|
| services.dysnomia.extraContainerProperties | An attribute set providing additional container settings in addition to the default properties
|
| services.librenms.distributedPoller.enable | Configure this LibreNMS instance as a distributed poller
|
| services.frp.instances.<name>.environmentFiles | List of paths files that follows systemd environmentfile structure
|
| users.extraUsers.<name>.linger | Whether to enable or disable lingering for this user
|
| services.crowdsec-firewall-bouncer.createRulesets | Whether to have the module create the appropriate firewall configuration
based on the bouncer settings
|
| services.prometheus.scrapeConfigs.*.tls_config | Configures the scrape request's TLS settings.
|
| services.qbittorrent.serverConfig | Free-form settings mapped to the qBittorrent.conf file in the profile
|
| hardware.openrazer.batteryNotifier | Settings for device battery notifications.
|
| services.bitwarden-directory-connector-cli.ldap | Options to configure the LDAP connection
|
| services.bitwarden-directory-connector-cli.sync | Options to configure what gets synced
|
| services.centrifugo.environmentFiles | Files to load environment variables from
|
| services.archisteamfarm.ipcSettings | Settings to write to IPC.config
|
| services.grafana.settings.security.content_security_policy_report_only | Set to true to add the Content-Security-Policy-Report-Only header to your requests
|
| services.nghttpx.backends.*.params.affinity | If "ip" is given, client IP based session affinity is
enabled
|
| i18n.extraLocaleSettings | A set of additional system-wide locale settings other than LANG
which can be configured with i18n.defaultLocale
|
| services.grafana.settings.security.disable_brute_force_login_protection | Set to true to disable brute force login protection.
|
| services.grafana.settings.security.strict_transport_security_subdomains | Set to true to enable HSTS includeSubDomains option
|
| services.nginx.recommendedOptimisation | Enable recommended optimisation settings.
|
| virtualisation.appvm.enable | This enables AppVMs and related virtualisation settings.
|
| services.transmission.credentialsFile | Path to a JSON file to be merged with the settings
|
| services.davis.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.davis.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.movim.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.slskd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.slskd.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.movim.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fluent-bit.configurationFile | Fluent Bit configuration
|
| services.snipe-it.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.snipe-it.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.akkoma.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.gancio.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fluidd.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fluidd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.gancio.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.akkoma.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.matomo.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.matomo.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.monica.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.monica.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| programs.ryzen-monitor-ng.enable | Whether to enable ryzen_monitor_ng, a userspace application for setting and getting Ryzen SMU (System Management Unit) parameters via the ryzen_smu kernel driver
|
| services.prometheus.alertmanager-ntfy.extraConfigFiles | Config files to merge into the settings defined in services.prometheus.alertmanager-ntfy.settings
|
| virtualisation.lxc.bridgeConfig | This is the config file for override lxc-net bridge default settings.
|
| services.xserver.desktopManager.surf-display.screensaverSettings | Screensaver settings, see man 1 xset for possible options.
|
| services.radicle.httpd.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.radicle.httpd.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.prometheus.exporters.ecoflow.scrapingInterval | Scrapping interval in seconds
|
| services.dolibarr.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.agorakit.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.librenms.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.kanboard.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fediwall.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.librenms.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.kanboard.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.fediwall.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.agorakit.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.dolibarr.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.mainsail.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.pixelfed.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.pixelfed.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.mainsail.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.grafana.settings.security.strict_transport_security_max_age_seconds | Sets how long a browser should cache HSTS in seconds
|
| services.anuko-time-tracker.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.anuko-time-tracker.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| virtualisation.graphics | Whether to run QEMU with a graphics window, or in nographic mode
|
| services.bookstack.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.bookstack.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.zabbixWeb.nginx.virtualHost.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.zabbixWeb.nginx.virtualHost.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.jirafeau.nginxConfig.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.jirafeau.nginxConfig.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.nginx.virtualHosts.<name>.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.nginx.virtualHosts.<name>.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| programs.captive-browser.browser | The shell (/bin/sh) command executed once the proxy starts
|
| services.fedimintd.<name>.nginx.config.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.fedimintd.<name>.nginx.config.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| networking.wireless.userControlled | Allow users of the wpa_supplicant group to control wpa_supplicant
through wpa_gui or wpa_cli
|
| services.stash.settings.security_tripwire_accessed_from_public_internet | Learn more at https://docs.stashapp.cc/networking/authentication-required-when-accessing-stash-from-the-internet/
|
| services.transmission.performanceNetParameters | Whether to enable tweaking of kernel parameters
to open many more connections at the same time
|
| services.limesurvey.nginx.virtualHost.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| services.limesurvey.nginx.virtualHost.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| virtualisation.rosetta.enable | Whether to enable Rosetta support
|
| virtualisation.libvirtd.onBoot | Specifies the action to be done to / on the guests when the host boots
|
| networking.wireless.userControlled.enable | Allow normal users to control wpa_supplicant through wpa_gui or wpa_cli
|
| services.misskey.reverseProxy.webserver.nginx.locations.<name>.recommendedProxySettings | Enable recommended proxy settings.
|
| services.misskey.reverseProxy.webserver.nginx.locations.<name>.recommendedUwsgiSettings | Enable recommended uwsgi settings.
|
| virtualisation.containerd.configFile | Path to containerd config file
|
| services.changedetection-io.environmentFile | Securely pass environment variables to changedetection-io
|
| networking.networkmanager.enable | Whether to use NetworkManager to obtain an IP address and other
configuration for all network interfaces that are not manually
configured
|
| services.prometheus.scrapeConfigs.*.http_sd_configs.*.tls_config | Configures the scrape request's TLS settings.
|
| programs.opengamepadui.powerstation.enable | Whether to enable Run PowerStation service for TDP control and performance settings.
.
|
| qt.platformTheme | Selects the platform theme to use for Qt applications
|
| services.hostapd.radios.<name>.networks.<name>.authentication.mode | Selects the authentication mode for this AP.
- "none": Don't configure any authentication
|
| virtualisation.oci-containers.containers.<name>.podman | Podman-specific settings in OCI containers
|
| services.prometheus.scrapeConfigs.*.consul_sd_configs.*.tls_config | Configures the Consul request's TLS settings.
|
| virtualisation.lxd.recommendedSysctlSettings | Enables various settings to avoid common pitfalls when
running containers requiring many file operations
|
| networking.networkmanager.ensureProfiles.secrets.entries.*.matchType | NetworkManager connection type
The NetworkManager configuration settings reference roughly corresponds to connection types
|
| virtualisation.oci-containers.containers.<name>.capabilities | Capabilities to configure for the container
|
| networking.networkmanager.ensureProfiles.profiles | Declaratively define NetworkManager profiles
|